🛡️ OESA-2026-2867 — aom
Description
aom security update
The Alliance for Open Media’s focus is to deliver a next-generation video format that is:
Security Fix(es):
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.(CVE-2026-56209)
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).(CVE-2026-56210)
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.(CVE-2026-56211)
Affected software
OESA-2026-2867 is recorded against 1 package.
- aom (fixed in 3.8.0-6.oe2403sp3)
Timeline and source
Published on 6 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.openeuler.org (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| aom | — | 3.8.0-6.oe2403sp3 |
References
Similar Threats
- Unknown ECHO-2e12-e6da-9a4b
- Unknown DEBIAN-CVE-2026-56208
- Unknown DEBIAN-CVE-2026-56209
- Unknown DEBIAN-CVE-2026-56210
- Unknown DEBIAN-CVE-2026-56211
More OESA 2026 advisories
Browse all of OESA 2026 in the advisory index.
Site Security Check
Is aom part of your stack?
OESA-2026-2867 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.