← All Advisories

CVE-2026-56210

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-56210

Key Details

CVECVE-2026-56210
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is low; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat AI Inference Server 3.3
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat AI Inference Server
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat OpenShift AI 3.5
Red HatRed Hat Hardened Images
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9
Red HatRed Hat Enterprise Linux AI 3.4 for RHEL 9
Red HatRed Hat Enterprise Linux AI 3.5 for RHEL 9
SubsystemsGeneral OT
SectorsMultiple

What to Know

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory). (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-56210
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-56210