Heap Overflow in libaom's AV1 Encoder LAP Mode
CVE-2026-56208 Published on June 19, 2026
Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.
Vulnerability Analysis
CVE-2026-56208 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and a high impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Products Associated with CVE-2026-56208
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-56208 are published in these products:
Affected Versions
Red Hat Enterprise Linux 10.0 Extended Update Support:- Version 0:140.13.0-1.el10_0 and below * is unaffected.
- Version 0:140.13.0-1.el7_9 and below * is unaffected.
- Version 0:140.13.0-1.el8_10 and below * is unaffected.
- Version 0:140.13.0-1.el8_4 and below * is unaffected.
- Version 0:140.13.0-1.el8_4 and below * is unaffected.
- Version 0:140.13.0-1.el8_6 and below * is unaffected.
- Version 0:140.13.0-1.el8_6 and below * is unaffected.
- Version 0:140.13.0-1.el8_8 and below * is unaffected.
- Version 0:140.13.0-1.el8_8 and below * is unaffected.
- Version 0:140.13.0-1.el9_8 and below * is unaffected.
- Version 0:140.13.0-1.el9_2 and below * is unaffected.
- Version 0:140.13.0-1.el9_4 and below * is unaffected.
- Version 0:140.13.0-1.el9_6 and below * is unaffected.
- Version 0:3.14.0-1.el9ai and below * is unaffected.
- Version 0:3.14.0-1.el9ai and below * is unaffected.
- Version 0:3.14.0-1.el9ai and below * is unaffected.
- Version 1787860580 and below * is unaffected.
- Version 1787772157 and below * is unaffected.
- Version 1787884873 and below * is unaffected.
- Version 1789508287 and below * is unaffected.
- Version 1789502493 and below * is unaffected.
- Version 1789504371 and below * is unaffected.
- Version 1789582776 and below * is unaffected.
- Version 3.14.0-0.1.hum1 and below * is unaffected.
- Version 1789137552 and below * is unaffected.
- Version 1789137548 and below * is unaffected.
- Version 1789137636 and below * is unaffected.
- Version 1789137548 and below * is unaffected.
- Version 1789137548 and below * is unaffected.
- Version 1789137641 and below * is unaffected.
- Version 1789137607 and below * is unaffected.
- Version 1789137636 and below * is unaffected.
- Version 1786611800 and below * is unaffected.
- Version 1787076778 and below * is unaffected.
- Version 1787077779 and below * is unaffected.
- Version 1787076481 and below * is unaffected.
- Version 1788197680 and below * is unaffected.
- Version 1788197530 and below * is unaffected.
- Version 1788197632 and below * is unaffected.
- Version 1788197747 and below * is unaffected.
- Version 1788197549 and below * is unaffected.
- Version 1788199622 and below * is unaffected.
- Version 1788197744 and below * is unaffected.
- Version 1788197677 and below * is unaffected.
- Version 1788198404 and below * is unaffected.
- Version 1788198407 and below * is unaffected.
- Version 1788197492 and below * is unaffected.
- Version 1788197542 and below * is unaffected.
- Version 1788197975 and below * is unaffected.
- Version 1788197512 and below * is unaffected.
- Version 1788197688 and below * is unaffected.
- Version 1788197385 and below * is unaffected.
- Version 1788198016 and below * is unaffected.
- Version 0:140.13.0-1.el10_0 and below * is unaffected.
- Version 0:140.13.0-1.el7_9 and below * is unaffected.
- Version 0:140.13.0-1.el8_10 and below * is unaffected.
- Version 0:140.13.0-1.el8_4 and below * is unaffected.
- Version 0:140.13.0-1.el8_4 and below * is unaffected.
- Version 0:140.13.0-1.el8_6 and below * is unaffected.
- Version 0:140.13.0-1.el8_6 and below * is unaffected.
- Version 0:140.13.0-1.el8_8 and below * is unaffected.
- Version 0:140.13.0-1.el8_8 and below * is unaffected.
- Version 0:140.13.0-1.el9_8 and below * is unaffected.
- Version 0:140.13.0-1.el9_2 and below * is unaffected.
- Version 0:140.13.0-1.el9_4 and below * is unaffected.
- Version 0:140.13.0-1.el9_6 and below * is unaffected.
- Version 0:3.14.0-1.el9ai and below * is unaffected.
- Version 0:3.14.0-1.el9ai and below * is unaffected.
- Version 0:3.14.0-1.el9ai and below * is unaffected.
- Version 3.14.0-0.1.hum1 and below * is unaffected.
- Version 1786611800 and below * is unaffected.
- Version 1787076778 and below * is unaffected.
- Version 1787077779 and below * is unaffected.
- Version 1787076481 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.