Description
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder-s SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.
CVSS 7.1EPSS 0.45199999999999996%Risque 0.74
Voir la source- Publication
- 2026-06-19 17:16:30
- Dernière modification
- 2026-08-11 22:17:31
- Vecteur
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H