{"id":"USN-8772-1","summary":"aom vulnerabilities","details":"It was discovered that AOM incorrectly handled the first-pass statistics\nbuffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use\nthis issue to cause a heap buffer overflow, leading to a denial of service\nor possibly execute arbitrary code. (CVE-2026-56208)\n\nIt was discovered that AOM incorrectly validated spatial and temporal\nlayer IDs in the SVC (Scalable Video Coding) encoder controls. An attacker\ncould possibly use this issue to write to an arbitrary memory address, read\nout-of-bounds heap memory, or execute arbitrary code. (CVE-2026-56209,\nCVE-2026-56210, CVE-2026-56211)","modified":"2026-09-16T20:27:34.125593287Z","published":"2026-09-16T09:29:07Z","related":["UBUNTU-CVE-2026-56208","UBUNTU-CVE-2026-56209","UBUNTU-CVE-2026-56210","UBUNTU-CVE-2026-56211"],"upstream":["CVE-2026-56208","CVE-2026-56209","CVE-2026-56210","CVE-2026-56211","UBUNTU-CVE-2026-56208","UBUNTU-CVE-2026-56209","UBUNTU-CVE-2026-56210","UBUNTU-CVE-2026-56211"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8772-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-56208"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-56209"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-56210"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-56211"}],"affected":[{"package":{"name":"aom","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/aom?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.0-1ubuntu0.1+esm1"}]}],"versions":["1.0.0.errata1-3build1","3.2.0-2","3.3.0-1","3.3.0-1ubuntu0.1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"aom-tools","binary_version":"3.3.0-1ubuntu0.1+esm1"},{"binary_name":"libaom3","binary_version":"3.3.0-1ubuntu0.1+esm1"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[{"id":"CVE-2026-56208","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-56209","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-56210"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-56211"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8772-1.json"}},{"package":{"name":"aom","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/aom?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.2-2ubuntu0.2"}]}],"versions":["3.6.1-1","3.7.0-1","3.7.1-1","3.8.1-1","3.8.2-2build1","3.8.2-2ubuntu0.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"aom-tools","binary_version":"3.8.2-2ubuntu0.2"},{"binary_name":"libaom3","binary_version":"3.8.2-2ubuntu0.2"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-56208","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-56209"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-56210"},{"id":"CVE-2026-56211","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8772-1.json"}},{"package":{"name":"aom","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/aom?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.1-2ubuntu0.1"}]}],"versions":["3.12.1-1","3.13.1-2"],"ecosystem_specific":{"binaries":[{"binary_version":"3.13.1-2ubuntu0.1","binary_name":"aom-tools"},{"binary_version":"3.13.1-2ubuntu0.1","binary_name":"libaom3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8772-1.json","cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-56208"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-56209"},{"id":"CVE-2026-56210","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-56211"}]}}}],"schema_version":"1.9.0"}