Skip to main content

Threats Tagged 'cve-2026-56211'

View all threats tagged with 'cve-2026-56211'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-56211

Threats Tagged 'cve-2026-56211'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat® AI Inference Server Model Optimization Tools

Join the discussion
0

This update for libaom fixes the following issues - CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap-based buffer overflow and a process crash (bsc#1268650). - CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). - CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out-of-bounds heap read (bsc#1268653). - CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655).

Join the discussion

CVE-2026-56211 is a high-severity remote code execution vulnerability in libaom, the reference AV1 codec implementation used in Red Hat Enterprise Linux AI 3.x for RHEL 9. The flaw arises from insufficient bounds validation in the AV1 encoder's SVC layer ID control, allowing crafted video frames to corrupt internal encoder structures. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames. Red Hat has released security updates addressing this vulnerability in libaom version 3.14.0-0.1.hum1 and later for multiple architectures. Users should apply these official patches to mitigate the risk.

Join the discussion

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.

Join the discussion

The OpenShift Compliance Operator v1.9.0 is now available. See the documentation for bug fix information: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/compliance-operator#compliance-operator-release-notes

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2026-56211
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses