Advisories ยป MGASA-2026-0410

Updated aom packages fix security vulnerabilities

Publication date: 16 Sep 2026
Modification date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56208 , CVE-2026-56209 , CVE-2026-56210 , CVE-2026-56211

Description

Heap buffer overflow in av1 encoder first-pass stats buffer via lap
mode. (CVE-2026-56208)
Arbitrary address write via svc layer context oob and cyclic refresh map
pointer hijack. (CVE-2026-56209)
Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id.
(CVE-2026-56210)
Remote code execution via svc layer context handling with
attacker-controlled frames. (CVE-2026-56211)
                

References

SRPMS

10/core

9/core