Back Linuxsecurity Mageia AOM Critical Heap Overflow and Remote Code Execution 2026
Artifactory Alert: Chained flaws let attackers gain admin control. Check your version now ×
Description: Heap buffer overflow in av1 encoder first-pass stats buffer via lap mode. (CVE-2026-56208) Arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack. (CVE-2026-56209) Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id. (CVE-2026-56210) Remote code execution via svc layer context handling with attacker-controlled frames. (CVE-2026-56211)
Description: Heap buffer overflow in av1 encoder first-pass stats buffer via lap mode. (CVE-2026-56208) Arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack. (CVE-2026-56209) Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id. (CVE-2026-56210) Remote code execution via svc layer context handling with attacker-controlled frames. (CVE-2026-56211)
- - - - - -
-
-
-
-
-
-
- 10/core/aom-3.13.1-1.1.mga10 - 9/core/aom-3.6.0-1.2.mga9
- 10/core/aom-3.13.1-1.1.mga10
- 9/core/aom-3.6.0-1.2.mga9
Publication date: 16 Sep 2026 URL: https: //advisories.mageia.org/MGASA-2026-0410.html Type: security CVE: CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
