Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-56210

Опубликовано: 19 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.1

Описание

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

РелизСтатусПримечание
devel

not-affected

3.14.1-1
esm-apps/focal

not-affected

code not present
esm-apps/jammy

released

3.3.0-1ubuntu0.1+esm1
jammy

needed

noble

released

3.8.2-2ubuntu0.2
questing

ignored

end of life, was needs-triage
resolute

released

3.13.1-2ubuntu0.1
upstream

released

3.14.0

Показывать по

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
3 месяца назад

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

CVSS3: 7.1
nvd
3 месяца назад

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

CVSS3: 7.1
debian
3 месяца назад

A heap-buffer-overflow read vulnerability was found in libaom, the ref ...

CVSS3: 7.1
github
3 месяца назад

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

suse-cvrf
3 месяца назад

Security update for libaom

7.1 High

CVSS3