Heap Overflow in libaom's AV1 Encoder LAP Mode CVE-2026-56208 Published on June 19, 2026
Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.
CVE-2026-56208 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and a high impact on availability.
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
HIGH
Timeline
Reported to Red Hat.
Made public.
Weakness Type
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Products Associated with CVE-2026-56208
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Version 0:140.13.0-1.el8_10 and below *
is unaffected.
Red Hat Enterprise Linux 9:
Version 0:140.13.0-1.el9_8 and below *
is unaffected.
Red Hat Enterprise Linux AI 3.5 for RHEL 9:
Version 0:3.14.0-1.el9ai and below *
is unaffected.
Red Hat Hardened Images:
Version 3.14.0-0.1.hum1 and below *
is unaffected.
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 7:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat Enterprise Linux 8:
Version 0:140.13.0-1.el8_10 and below *
is unaffected.
Red Hat Enterprise Linux AI 3.5 for RHEL 9:
Version 0:3.14.0-1.el9ai and below *
is unaffected.
Red Hat Hardened Images:
Version 3.14.0-0.1.hum1 and below *
is unaffected.
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 7:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Exploit Probability
EPSS
0.28%
Percentile
19.64%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.