Status: UPDATED
| Advisory ID: CVE-2026-56210
Key Details
| CVE | CVE-2026-56210 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is low; integrity impact is none; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-125 (Out-of-bounds Read) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory). (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References