CVE-2026-56210: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux AI 3.3 for RHEL 9
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
AI Analysis
Technical Summary
The vulnerability CVE-2026-56210 affects libaom, the reference AV1 codec implementation, specifically in the SVC layer ID control function where a missing bounds check permits setting a spatial_layer_id beyond the configured number of layers. This results in an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker able to influence SVC encoder parameters in a network-facing service could exploit this flaw to leak heap memory contents or cause a segmentation fault leading to denial of service. Red Hat has issued security advisories RHSA-2026:30814 and RHSA-2026:42875, providing updated RPM packages (aom and libaom version 3.14.0-0.1.hum1 and 3.14.0-1.el9ai) that fix this vulnerability. The affected product is Red Hat Enterprise Linux AI 3.3 and 3.5 for RHEL 9, with affected versions starting from 3.5 and above. The CVSS v3.1 score is 7.1, indicating high severity with network attack vector, low attack complexity, no privileges required, user interaction required, and impact limited to confidentiality loss and high availability impact.
Potential Impact
The vulnerability allows an attacker who can influence SVC encoder parameters in a network-facing service to cause an out-of-bounds heap read of approximately 40,728 bytes. This can lead to information disclosure through heap content leakage or denial of service due to segmentation faults from accessing unmapped memory. The CVSS score of 7.1 reflects a high severity impact with confidentiality loss and service disruption possible.
Mitigation Recommendations
Red Hat has released security updates that fix this vulnerability. Users of Red Hat Enterprise Linux AI 3.3 and 3.5 for RHEL 9 should apply the updated RPM packages aom and libaom version 3.14.0-0.1.hum1 or 3.14.0-1.el9ai as provided in advisories RHSA-2026:30814 and RHSA-2026:42875. Before applying these updates, ensure all previously released errata relevant to your system have been applied. There is no indication that the vulnerability is mitigated without applying these updates. No known exploits are reported in the wild at this time.
CVE-2026-56210: Out-of-bounds Read in Red Hat Red Hat Enterprise Linux AI 3.3 for RHEL 9
Description
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
CVSS v3.1
Score 7.1high
Affected software
Red Hat
Red Hat Enterprise Linux AI 3.3 for RHEL 9
Red Hat
Red Hat Enterprise Linux AI 3.4 for RHEL 9
Red Hat
Red Hat Enterprise Linux AI 3.5 for RHEL 9
Red Hat
Red Hat AI Inference Server 3.2
Red Hat
Red Hat AI Inference Server 3.2
Red Hat
Red Hat AI Inference Server 3.2
Red Hat
Red Hat Hardened Images
Red Hat
Red Hat OpenShift AI 3.4
Red Hat
Red Hat OpenShift AI 3.4
Red Hat
Red Hat OpenShift AI 3.4
Red Hat
Red Hat OpenShift AI 3.4
Red Hat
Red Hat AI Inference Server
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat OpenShift AI (RHOAI)
Red Hat
Red Hat OpenShift AI (RHOAI)
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-56210 affects libaom, the reference AV1 codec implementation, specifically in the SVC layer ID control function where a missing bounds check permits setting a spatial_layer_id beyond the configured number of layers. This results in an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker able to influence SVC encoder parameters in a network-facing service could exploit this flaw to leak heap memory contents or cause a segmentation fault leading to denial of service. Red Hat has issued security advisories RHSA-2026:30814 and RHSA-2026:42875, providing updated RPM packages (aom and libaom version 3.14.0-0.1.hum1 and 3.14.0-1.el9ai) that fix this vulnerability. The affected product is Red Hat Enterprise Linux AI 3.3 and 3.5 for RHEL 9, with affected versions starting from 3.5 and above. The CVSS v3.1 score is 7.1, indicating high severity with network attack vector, low attack complexity, no privileges required, user interaction required, and impact limited to confidentiality loss and high availability impact.
Potential Impact
The vulnerability allows an attacker who can influence SVC encoder parameters in a network-facing service to cause an out-of-bounds heap read of approximately 40,728 bytes. This can lead to information disclosure through heap content leakage or denial of service due to segmentation faults from accessing unmapped memory. The CVSS score of 7.1 reflects a high severity impact with confidentiality loss and service disruption possible.
Mitigation Recommendations
Red Hat has released security updates that fix this vulnerability. Users of Red Hat Enterprise Linux AI 3.3 and 3.5 for RHEL 9 should apply the updated RPM packages aom and libaom version 3.14.0-0.1.hum1 or 3.14.0-1.el9ai as provided in advisories RHSA-2026:30814 and RHSA-2026:42875. Before applying these updates, ensure all previously released errata relevant to your system have been applied. There is no indication that the vulnerability is mitigated without applying these updates. No known exploits are reported in the wild at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-19T15:50:16.801Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-56210","vendor":"Red Hat"}]
Threat ID: 6a3576cef198dc38c1c38ecd
Added to database: 06/19/2026, 17:05:18 UTC
Last enriched: 08/17/2026, 15:07:17 UTC
Last updated: 09/17/2026, 10:01:32 UTC
Views: 251
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.