A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird | Jul 8, 2026 | Jul 8, 2026 |
| Amazon_linux_2023 | — | Upgrade firefoxUpgrade firefox-debugsourceUpgrade firefox-debuginfo | Jul 8, 2026 | Jun 19, 2026 |
| Debian | — | Upgrade aom | Aug 5, 2026 | Aug 5, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 19, 2026 |
| Ubuntu | — | Upgrade libaom-devUpgrade aom-tools (Ubuntu Pro)Upgrade aom-toolsUpgrade libaom-dev (Ubuntu Pro)Upgrade libaom3 (Ubuntu Pro)Upgrade libaom3 | Sep 16, 2026 | Jun 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub