DSA-6411-1 aom - security update
Multiple vulnerabilities were discovered in aom, the reference implementation of the AV1 video codec. All of them affect the encoder; applications that only decode AV1 video are not affected. CVE-2026-56208 In look-ahead processing (LAP) mode the first-pass statistics buffer was sized from the configured lag-in-frames alone, leaving it shorter than the longest group of pictures the encoder may analyse. Together with an off-by-one in the number of frames considered, this allowed the encoder to read and write outside the allocation, resulting in denial of service or potentially the execution of arbitrary code. CVE-2026-56209, CVE-2026-56210, CVE-2026-56211 The AOME_SET_SPATIAL_LAYER_ID and AV1E_SET_SVC_LAYER_ID codec controls did not validate the supplied scalable video coding (SVC) layer identifiers against the number of layers actually configured. A negative or too large identifier led to an out-of-bounds read of the layer context array, an out-of-bounds write through the cyclic refresh map pointer, and potentially the execution of arbitrary code. Exploitation requires an application that allows an attacker to influence the encoder's SVC configuration. Additionally this update validates the configured number of spatial and temporal layers, which the affected version accepted without any range check. https://security-tracker.debian.org/tracker/DSA-6411-1
CSIRTS triage
- What
- Multiple vulnerabilities in aom AV1 video encoder allow buffer overflow, memory corruption, and denial of service through improper SVC layer validation.
- Who is affected
- Systems using aom encoder for AV1 video processing are vulnerable; decoder-only deployments are not affected.
- Urgency
- Buffer overflow and arbitrary code execution in encoder warrant priority patching.
- Action
- Update aom to the patched version addressing CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, and CVE-2026-56211.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch aom
Get an email when a new aom advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00322.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-562080.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-562090.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-562100.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-562110.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56208 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56209 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56210 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56211 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Debian Security Advisories
- highDSA-6496-1 nginx - security update2026-09-12
- unknownDSA-6495-1 spip - security update2026-09-11
- unknownDSA-6493-1 libevent - security update2026-09-11
- unknownDSA-6494-1 kamailio - security update2026-09-11
- unknownDSA-6492-1 ruby-rack - security update2026-09-10