Updated aom packages fix security vulnerabilities
Publication date: 16 Sep 2026Modification date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56208 , CVE-2026-56209 , CVE-2026-56210 , CVE-2026-56211
Description
Heap buffer overflow in av1 encoder first-pass stats buffer via lap
mode. (CVE-2026-56208)
Arbitrary address write via svc layer context oob and cyclic refresh map
pointer hijack. (CVE-2026-56209)
Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id.
(CVE-2026-56210)
Remote code execution via svc layer context handling with
attacker-controlled frames. (CVE-2026-56211)
References
- https://bugs.mageia.org/show_bug.cgi?id=36170
- https://lists.debian.org/debian-security-announce/2026/msg00322.html
- https://www.cve.org/CVERecord?id=CVE-2026-56208
- https://www.cve.org/CVERecord?id=CVE-2026-56209
- https://www.cve.org/CVERecord?id=CVE-2026-56210
- https://www.cve.org/CVERecord?id=CVE-2026-56211
SRPMS
10/core
- aom-3.13.1-1.1.mga10
9/core
- aom-3.6.0-1.2.mga9