<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:37:10 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-56210 — Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-56210</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat Enterprise Linux AI 3.3 for RHEL 9, Red Hat Enterprise Linux AI 3.4 for RHEL 9, Red Hat Enterprise Linux AI 3.5 for RHEL 9, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat Hardened Images, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 3.5 and 4 more&lt;/p&gt;
&lt;p&gt;A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat Enterprise Linux AI 3.3 for RHEL 9, Red Hat Enterprise Linux AI 3.4 for RHEL 9, Red Hat Enterprise Linux AI 3.5 for RHEL 9, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat Hardened Images, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.4, Red Hat OpenShift AI 3.5 and 4 more&lt;/p&gt;
&lt;p&gt;A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-56210</guid>
    </item>
  </channel>
</rss>
