Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: aom: * aom-3.14.0-0.1.hum1 (aarch64, x86_64) * libaom-3.14.0-0.1.hum1 (aarch64, x86_64) * libaom-devel-3.14.0-0.1.hum1 (aarch64, x86_64) * libaom-devel-docs-3.14.0-0.1.hum1 (aarch64, x86_64) * aom-3.14.0-0.1.hum1.src (src) Security Fix(es): aom: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211
AI Analysis
Technical Summary
This Red Hat security advisory addresses four vulnerabilities (CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211) in the aom package, which is part of Red Hat Hardened Images and Red Hat Enterprise Linux AI 3.5. The affected packages include aom and libaom RPMs version 3.14.0-0.1.hum1 and 3.14.0-1.el9ai for multiple architectures (aarch64, x86_64, s390x, ppc64le). The vulnerabilities relate to memory safety issues such as heap-based buffer overflows and out-of-bounds reads/writes (CWE-122, CWE-787, CWE-125). Red Hat has released updated RPMs to address these issues. The packages are internal build artifacts and supported only within the Red Hat AI application platform. No CVSS scores are published, but the severity is rated high/important by Red Hat. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities affect the aom package used in Red Hat Hardened Images and Red Hat Enterprise Linux AI 3.5, potentially leading to memory safety issues such as buffer overflows and out-of-bounds memory access. These issues could allow attackers to cause application crashes or potentially execute arbitrary code if exploited. The affected packages span multiple architectures (aarch64, x86_64, s390x, ppc64le). No known active exploitation has been reported. The impact is considered high by Red Hat, indicating significant risk if unpatched.
Mitigation Recommendations
Red Hat has released updated RPM packages (aom-3.14.0-0.1.hum1 and aom-3.14.0-1.el9ai) that fix the identified vulnerabilities. Users of Red Hat Hardened Images and Red Hat Enterprise Linux AI 3.5 should apply these updates promptly. The RPM packages are internal build artifacts and supported only as part of the Red Hat AI application platform. Before applying the update, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisories (RHSA-2026:30814 and RHSA-2026:42875) and the Red Hat images portal for detailed update instructions. No additional mitigation steps are indicated by the vendor.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: aom: * aom-3.14.0-0.1.hum1 (aarch64, x86_64) * libaom-3.14.0-0.1.hum1 (aarch64, x86_64) * libaom-devel-3.14.0-0.1.hum1 (aarch64, x86_64) * libaom-devel-docs-3.14.0-0.1.hum1 (aarch64, x86_64) * aom-3.14.0-0.1.hum1.src (src) Security Fix(es): aom: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory addresses four vulnerabilities (CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211) in the aom package, which is part of Red Hat Hardened Images and Red Hat Enterprise Linux AI 3.5. The affected packages include aom and libaom RPMs version 3.14.0-0.1.hum1 and 3.14.0-1.el9ai for multiple architectures (aarch64, x86_64, s390x, ppc64le). The vulnerabilities relate to memory safety issues such as heap-based buffer overflows and out-of-bounds reads/writes (CWE-122, CWE-787, CWE-125). Red Hat has released updated RPMs to address these issues. The packages are internal build artifacts and supported only within the Red Hat AI application platform. No CVSS scores are published, but the severity is rated high/important by Red Hat. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities affect the aom package used in Red Hat Hardened Images and Red Hat Enterprise Linux AI 3.5, potentially leading to memory safety issues such as buffer overflows and out-of-bounds memory access. These issues could allow attackers to cause application crashes or potentially execute arbitrary code if exploited. The affected packages span multiple architectures (aarch64, x86_64, s390x, ppc64le). No known active exploitation has been reported. The impact is considered high by Red Hat, indicating significant risk if unpatched.
Mitigation Recommendations
Red Hat has released updated RPM packages (aom-3.14.0-0.1.hum1 and aom-3.14.0-1.el9ai) that fix the identified vulnerabilities. Users of Red Hat Hardened Images and Red Hat Enterprise Linux AI 3.5 should apply these updates promptly. The RPM packages are internal build artifacts and supported only as part of the Red Hat AI application platform. Before applying the update, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisories (RHSA-2026:30814 and RHSA-2026:42875) and the Red Hat images portal for detailed update instructions. No additional mitigation steps are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:30814
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-56209","CVE-2026-56210","CVE-2026-56211"]
- Cvss Version
- null
Threat ID: 6a42ed8127e9c79719946efa
Added to database: 06/29/2026, 22:11:13 UTC
Last enriched: 08/06/2026, 22:50:05 UTC
Last updated: 08/13/2026, 12:41:11 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.