CVE-2026-56208Disclosure

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-25: 1Mentions · 2026-07-03: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-06-25: 1Technical Details · 2026-07-03: 106-2507-03
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-251
Disclosure1
2026-07-031
Patch1
Full discourse2 posts
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-56208](https://access.redhat.com/errata/RHSA-2026:30814) A heap buffer overflow vulnera... https://access.redhat.com/errata/RHSA-2026:30814 #PatchManagement #Vulnerability #CVE

    Post summary

    Red Hat issues a patch for CVE‑2026‑56208, a heap buffer overflow vulnerability, with no evidence of exploits or PoC.

    0000050
    7 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-56208 (CVSS 7.6) - Heap buffer overflow in libaom AV1 codec. 232-byte OOB write per frame after LAP mode bypass. Affects transcoding services & WebRTC. Potential RCE. Patch immediately. #CVE #PatchNow https://t.co/rq3z3SeeWK

    Post summary

    A new vulnerability, CVE-2026-56208, impacts the libaom AV1 codec with a heap buffer overflow that could lead to remote code execution, and users are urged to patch immediately.

    0000061
    52 followersView on X

Explore more