A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird | Jul 8, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debuginfoUpgrade firefox-debugsource | Jul 8, 2026 | Jun 19, 2026 |
| Debian | — | Upgrade aom | Aug 5, 2026 | Aug 5, 2026 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade firefox-x11Upgrade firefox-debuginfoNo solution existsUpgrade firefox | Jul 17, 2026 | Jun 19, 2026 |
| Rocky_linux | — | Upgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade firefoxUpgrade firefox-x11 | Jul 31, 2026 | Jul 29, 2026 |
| Ubuntu | — | Upgrade libaom3 (Ubuntu Pro)Upgrade aom-tools (Ubuntu Pro)Upgrade libaom-dev (Ubuntu Pro)Upgrade libaom-devUpgrade libaom3Upgrade aom-tools | Sep 16, 2026 | Jun 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub