CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56210

unknowncovered by 1 sourcefirst seen 2026-08-05
Multiple vulnerabilities were discovered in aom, the reference implementation of the AV1 video codec. All of them affect the encoder; applications that only decode AV1 video are not affected. CVE-2026-56208 In look-ahead processing (LAP) mode the first-pass statistics buffer was sized from the configured lag-in-frames alone, leaving it shorter than the longest group of pictures the encoder may analyse. Together with an off-by-one in the number of frames considered, this allowed the encoder to read and write outside the allocation, resulting in denial of service or potentially the execution of arbitrary code. CVE-2026-56209, CVE-2026-56210, CVE-2026-56211 The AOME_SET_SPATIAL_LAYER_ID and AV1E_SET_SVC_LAYER_ID codec controls did not validate the supplied scalable video coding (SVC) layer identifiers against the number of layers actually configured. A negative or too large identifier led to an out-of-bounds read of the layer context array, an out-of-bounds write through the cyclic refresh map pointer, and potentially the execution of arbitrary code. Exploitation requires an application that allows an attacker to influence the encoder's SVC configuration. Additionally this update validates the configured number of spatial and temporal layers, which the affected version accepted without any range check. https://security-tracker.debian.org/tracker/DSA-6411-1

⚡ Watch CVE-2026-56210

Get an email if CVE-2026-56210 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-56210

CVE.org record

Embed the live status

CVE-2026-56210 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56210 status](https://www.csirts.com/badge/CVE-2026-56210)](https://www.csirts.com/cve/CVE-2026-56210)