CVE-2026-56211: Out-of-bounds Write in Red Hat Red Hat Enterprise Linux AI 3.5 for RHEL 9
CVE-2026-56211 is a high-severity remote code execution vulnerability in libaom, the AV1 codec implementation used in Red Hat Enterprise Linux AI 3.5 for RHEL 9. The flaw arises from insufficient bounds validation in the AV1 encoder's SVC layer ID control, allowing crafted video frames to corrupt internal encoder structures. Exploitation requires the target to use libaom with SVC encoding enabled and accept attacker-supplied video frames. Red Hat has released updated RPM packages including libaom 3.14.0-1.el9ai that address this vulnerability.
AI Analysis
Technical Summary
This vulnerability in libaom's AV1 encoder involves an out-of-bounds write due to improper bounds checking of the SVC layer ID control. An attacker supplying specially crafted video frames can cause memory corruption overlapping internal encoder layer context structures. In fork-based video processing services, this can lead to hijacking of the cyclic refresh map pointer, brute forcing the process base address via crash oracles, and redirecting control flow to achieve arbitrary command execution. The vulnerability affects all versions of Red Hat Enterprise Linux AI 3.5 for RHEL 9 using libaom with SVC encoding enabled. Red Hat has issued security advisories and RPM updates (version 3.14.0-1.el9ai) to fix this issue.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code on affected systems, potentially leading to full system compromise. The vulnerability impacts confidentiality, integrity, and availability, as indicated by the CVSS vector (Confidentiality: Low, Integrity: High, Availability: High). Exploitation requires user interaction (UI:R) and high attack complexity (AC:H), with no privileges required (PR:N). No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated RPM packages for libaom (version 3.14.0-1.el9ai) that address CVE-2026-56211. Users of Red Hat Enterprise Linux AI 3.5 for RHEL 9 should apply these updates promptly. The updates are available via Red Hat's official errata channels and image repositories. Before applying, ensure all previous relevant errata are installed. No alternative mitigations or workarounds are specified in the vendor advisory.
CVE-2026-56211: Out-of-bounds Write in Red Hat Red Hat Enterprise Linux AI 3.5 for RHEL 9
Description
CVE-2026-56211 is a high-severity remote code execution vulnerability in libaom, the AV1 codec implementation used in Red Hat Enterprise Linux AI 3.5 for RHEL 9. The flaw arises from insufficient bounds validation in the AV1 encoder's SVC layer ID control, allowing crafted video frames to corrupt internal encoder structures. Exploitation requires the target to use libaom with SVC encoding enabled and accept attacker-supplied video frames. Red Hat has released updated RPM packages including libaom 3.14.0-1.el9ai that address this vulnerability.
CVSS v3.1
Score 7.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in libaom's AV1 encoder involves an out-of-bounds write due to improper bounds checking of the SVC layer ID control. An attacker supplying specially crafted video frames can cause memory corruption overlapping internal encoder layer context structures. In fork-based video processing services, this can lead to hijacking of the cyclic refresh map pointer, brute forcing the process base address via crash oracles, and redirecting control flow to achieve arbitrary command execution. The vulnerability affects all versions of Red Hat Enterprise Linux AI 3.5 for RHEL 9 using libaom with SVC encoding enabled. Red Hat has issued security advisories and RPM updates (version 3.14.0-1.el9ai) to fix this issue.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code on affected systems, potentially leading to full system compromise. The vulnerability impacts confidentiality, integrity, and availability, as indicated by the CVSS vector (Confidentiality: Low, Integrity: High, Availability: High). Exploitation requires user interaction (UI:R) and high attack complexity (AC:H), with no privileges required (PR:N). No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated RPM packages for libaom (version 3.14.0-1.el9ai) that address CVE-2026-56211. Users of Red Hat Enterprise Linux AI 3.5 for RHEL 9 should apply these updates promptly. The updates are available via Red Hat's official errata channels and image repositories. Before applying, ensure all previous relevant errata are installed. No alternative mitigations or workarounds are specified in the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-19T15:50:16.801Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-56211","vendor":"Red Hat"}]
Threat ID: 6a3576d1f198dc38c1c38f51
Added to database: 06/19/2026, 17:05:21 UTC
Last enriched: 08/02/2026, 20:38:35 UTC
Last updated: 08/02/2026, 20:38:35 UTC
Views: 186
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.