Skip to content
Critical AOM Vulnerabilities Enable Remote Code Execution

Critical AOM Vulnerabilities Enable Remote Code Execution

First seen 16 Sep 2026, 18:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 17:29 UTC
  • Four critical CVEs identified in AOM library: CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211.
  • Vulnerabilities allow for heap buffer overflow and remote code execution via manipulated video frames.
  • Immediate system updates are recommended to mitigate the risks associated with these vulnerabilities.

Multiple vulnerabilities in the AOM (AV1 Video Codec) library have been discovered, affecting various systems. The issues include a heap buffer overflow (CVE-2026-56208), arbitrary memory writes (CVE-2026-56209), and potential remote code execution (CVE-2026-56211). Attackers can exploit these vulnerabilities through Look-Ahead Processing (LAP) mode and SVC (Scalable Video Coding) encoder controls. The flaws allow for out-of-bounds memory access and can lead to denial of service or arbitrary code execution. Affected systems include those utilizing the AOM library in video processing applications. Users are advised to update their systems to mitigate these vulnerabilities. The vulnerabilities were disclosed on June 19, 2026, and have been confirmed by multiple sources.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-06-19
CVE disclosures for AOM vulnerabilities
Four critical vulnerabilities in the AOM library were published, affecting various systems and allowing remote code execution.
Ubuntu
2026-06-19
CVE-2026-56210 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-19
CVE-2026-56208 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-19
CVE-2026-56211 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-19
CVE-2026-56209 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
Security advisories published
Ubuntu and Mageia released advisories detailing the vulnerabilities and urging users to update their systems.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-56208 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed