CVE-2026-56209
Publication date 19 June 2026
Last updated 16 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| aom | 26.04 LTS resolute |
Fixed 3.13.1-2ubuntu0.1
|
| 24.04 LTS noble |
Fixed 3.8.2-2ubuntu0.2
|
|
| 22.04 LTS jammy |
Fixed 3.3.0-1ubuntu0.1+esm1
|
|
| 20.04 LTS focal |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialSeverity score breakdown
CVSS version: CVSS v3.0
Base score
7.1 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8772-1
- AOM vulnerabilities
- 16 September 2026