Heap Overflow in libaom's AV1 Encoder LAP Mode CVE-2026-56208 Published on June 19, 2026
Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.
CVE-2026-56208 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and a high impact on availability.
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
HIGH
Timeline
Reported to Red Hat.
Made public.
Weakness Type
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Products Associated with CVE-2026-56208
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Red Hat Enterprise Linux 10.0 Extended Update Support:
Version 0:140.13.0-1.el10_0 and below *
is unaffected.
Red Hat Enterprise Linux 7 Extended Lifecycle Support:
Version 0:140.13.0-1.el7_9 and below *
is unaffected.
Red Hat Enterprise Linux 8:
Version 0:140.13.0-1.el8_10 and below *
is unaffected.
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support:
Version 0:140.13.0-1.el8_4 and below *
is unaffected.
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On:
Version 0:140.13.0-1.el8_4 and below *
is unaffected.
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support:
Version 0:140.13.0-1.el8_6 and below *
is unaffected.
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On:
Version 0:140.13.0-1.el8_6 and below *
is unaffected.
Red Hat Enterprise Linux 8.8 Telecommunications Update Service:
Version 0:140.13.0-1.el8_8 and below *
is unaffected.
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions:
Version 0:140.13.0-1.el8_8 and below *
is unaffected.
Red Hat Enterprise Linux 9:
Version 0:140.13.0-1.el9_8 and below *
is unaffected.
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions:
Version 0:140.13.0-1.el9_2 and below *
is unaffected.
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions:
Version 0:140.13.0-1.el9_4 and below *
is unaffected.
Red Hat Enterprise Linux 9.6 Extended Update Support:
Version 0:140.13.0-1.el9_6 and below *
is unaffected.
Red Hat Enterprise Linux AI 3.3 for RHEL 9:
Version 0:3.14.0-1.el9ai and below *
is unaffected.
Red Hat Enterprise Linux AI 3.4 for RHEL 9:
Version 0:3.14.0-1.el9ai and below *
is unaffected.
Red Hat Enterprise Linux AI 3.5 for RHEL 9:
Version 0:3.14.0-1.el9ai and below *
is unaffected.
Red Hat Hardened Images:
Version 3.14.0-0.1.hum1 and below *
is unaffected.
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat AI Inference Server:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat Enterprise Linux Server (v. 7 ELS):
Red Hat Enterprise Linux AI 3.3 for RHEL 9:
Red Hat Enterprise Linux AI 3.4 for RHEL 9:
Red Hat Enterprise Linux AI 3.5 for RHEL 9:
Red Hat Enterprise Linux AppStream EUS (v. 10.0):
Red Hat Enterprise Linux AppStream (v. 8):
Red Hat Enterprise Linux AppStream AUS (v.8.4):
Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4):
Red Hat Enterprise Linux AppStream AUS (v.8.6):
Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6):
Red Hat Enterprise Linux AppStream E4S (v.8.8):
Red Hat Enterprise Linux AppStream TUS (v.8.8):
Red Hat Enterprise Linux AppStream E4S (v.9.2):
Red Hat Enterprise Linux AppStream E4S (v.9.4):
Red Hat Enterprise Linux AppStream EUS (v.9.6):
Red Hat Enterprise Linux AppStream (v. 9):
Red Hat Hardened Images:
Exploit Probability
EPSS
0.28%
Percentile
19.64%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.