Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-56208

около 1 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2026-56208

около 1 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-56208

около 1 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-56208

около 1 месяца назад

A heap buffer overflow vulnerability was found in libaom, the referenc ...

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-mgv2-4j37-m3x6

около 1 месяца назад

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21061-1

около 1 месяца назад

Security update for libaom

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3224-1

8 дней назад

Security update for SVT-AV1, libyuv0, libaom3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2829-1

22 дня назад

Security update for libaom

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47105

4 дня назад

ELSA-2026-47105: firefox security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-56208

A heap buffer overflow vulnerability was found in libaom, the referenc ...

CVSS3: 7.6
0%
Низкий
около 1 месяца назад
github логотип
GHSA-mgv2-4j37-m3x6

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

CVSS3: 7.6
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21061-1

Security update for libaom

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3224-1

Security update for SVT-AV1, libyuv0, libaom3

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:2829-1

Security update for libaom

22 дня назад
oracle-oval логотип
ELSA-2026-47105

ELSA-2026-47105: firefox security update (IMPORTANT)

4 дня назад

Уязвимостей на страницу