UbuntuUpdates.org

Package "libaom-dev"

Name: libaom-dev

Description:

AV1 Video Codec Library -- Development Files

Latest version: 3.13.1-2ubuntu0.1
Release: resolute (26.04)
Level: security
Repository: main
Head package: aom
Homepage: https://aomedia.googlesource.com/aom/

Links


Download "libaom-dev"


Other versions of "libaom-dev" in Resolute

Repository Area Version
base main 3.13.1-2
updates main 3.13.1-2ubuntu0.1

Changelog

Version: 3.13.1-2ubuntu0.1 2026-09-16 10:07:42 UTC

aom (3.13.1-2ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow in LAP mode
    - debian/patches/CVE-2026-56208.patch: handle buffer pointer in LAP
      mode to avoid buffer overflow in av1/encoder/encoder.h,
      av1/encoder/firstpass.c, av1/encoder/pass2_strategy.c,
      test/encode_api_test.cc.
    - CVE-2026-56208
  * SECURITY UPDATE: Missing bounds check on SVC layer ID controls
    - debian/patches/CVE-2026-56209_56210_56211.patch: check for invalid
      parameters for SVC layer ID setting in aom/aomcx.h,
      av1/av1_cx_iface.c, test/encode_api_test.cc.
    - CVE-2026-56209
    - CVE-2026-56210
    - CVE-2026-56211

 -- Allen Huang Mon, 14 Sep 2026 17:14:58 +0100

CVE-2026-56208 A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (
CVE-2026-56209 An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Vid
CVE-2026-56210 A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Vi
CVE-2026-56211 A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder'



About   -   Send Feedback to @ubuntu_updates