CVE-2026-56208

HIGH
Published June 19, 2026

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a...

Full CISO analysis pending enrichment.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
vLLM pip No patch
84.6K 130 dependents Pushed 5d ago 23% patched ~51d to patch Full package profile →
aom No patch
aom-main No patch
firefox No patch
rhai/base-image-cpu-rhel9 No patch
rhai/base-image-cuda-12.9-rhel9 No patch
rhai/base-image-cuda-13.0-rhel9 No patch
rhai/base-image-gaudi-rhel9 No patch
rhai/base-image-neuron-rhel9 No patch
rhai/base-image-rocm-6.4-rhel9 No patch
rhai/base-image-rocm-7.0-rhel9 No patch
rhai/base-image-rocm-7.1-rhel9 No patch
rhai/base-image-spyre-rhel9 No patch
rhai/base-image-tpu-rhel9 No patch
rhaii/model-opt-cuda-rhel9 No patch
rhaiis/model-opt-cuda-rhel9 No patch
rhoai/odh-automl-rhel9 No patch
rhoai/odh-autorag-rhel9 No patch
rhoai/odh-kserve-autogluon-server-rhel9 No patch
rhoai/odh-llama-stack-core-rhel9 No patch
rhoai/odh-llm-d-kv-cache-rhel9 No patch
rhoai/odh-mlserver-rhel9 No patch
rhoai/odh-spark-operator-rhel9 No patch
rhoai/odh-th06-cpu-torch210-py312-rhel9 No patch
rhoai/odh-th06-cpu-torch291-py312-rhel9 No patch
rhoai/odh-th06-cuda130-torch210-py312-rhel9 No patch
rhoai/odh-th06-cuda130-torch291-py312-rhel9 No patch
rhoai/odh-th06-rocm64-torch291-py312-rhel9 No patch
rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 No patch
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 No patch
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 No patch
rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9 No patch
rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9 No patch
rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9 No patch
rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 No patch
thunderbird No patch

How severe is it?

CVSS 3.1
7.6 / 10
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
N/A

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI Required
S Unchanged
C Low
I Low
A High

What should I do?

No patch available

Monitor for updates. Consider compensating controls or temporary mitigations.

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2026-56208?

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

Is CVE-2026-56208 actively exploited?

No confirmed active exploitation of CVE-2026-56208 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-56208?

No patch is currently available. Monitor vendor advisories for updates.

What is the CVSS score for CVE-2026-56208?

CVE-2026-56208 has a CVSS v3.1 base score of 7.6 (HIGH).

What are the technical details?

Original Advisory

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

Weaknesses (CWE)

CWE-122 — Heap-based Buffer Overflow: A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

  • Pre-design: Use a language or compiler that performs automatic bounds checking.
  • [Architecture and Design] Use an abstraction library to abstract away risky APIs. Not a complete solution.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Timeline

Published
June 19, 2026
Last Modified
July 3, 2026
First Seen
July 3, 2026

Related Vulnerabilities