Debian dsa-6411 : aom-tools - security update

high Nessus Plugin ID 332088

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6411 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6411-1 [email protected] https://www.debian.org/security/ Aron Xu August 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : aom CVE ID : CVE-2026-56208 CVE-2026-56209 CVE-2026-56210 CVE-2026-56211 Debian Bug : 1140428

Multiple vulnerabilities were discovered in aom, the reference implementation of the AV1 video codec. All of them affect the encoder;
applications that only decode AV1 video are not affected.

CVE-2026-56208

In look-ahead processing (LAP) mode the first-pass statistics buffer was sized from the configured lag-in-frames alone, leaving it shorter than the longest group of pictures the encoder may analyse. Together with an off-by-one in the number of frames considered, this allowed the encoder to read and write outside the allocation, resulting in denial of service or potentially the execution of arbitrary code.

CVE-2026-56209, CVE-2026-56210, CVE-2026-56211

The AOME_SET_SPATIAL_LAYER_ID and AV1E_SET_SVC_LAYER_ID codec controls did not validate the supplied scalable video coding (SVC) layer identifiers against the number of layers actually configured.
A negative or too large identifier led to an out-of-bounds read of the layer context array, an out-of-bounds write through the cyclic refresh map pointer, and potentially the execution of arbitrary code. Exploitation requires an application that allows an attacker to influence the encoder's SVC configuration.

Additionally this update validates the configured number of spatial and temporal layers, which the affected version accepted without any range check.

For the stable distribution (trixie), these problems have been fixed in version 3.12.1-1+deb13u1.

We recommend that you upgrade your aom packages.

For the detailed security status of aom please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/aom

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the aom-tools packages.

See Also

https://packages.debian.org/source/trixie/aom

https://security-tracker.debian.org/tracker/CVE-2026-56208

https://security-tracker.debian.org/tracker/CVE-2026-56209

https://security-tracker.debian.org/tracker/CVE-2026-56210

https://security-tracker.debian.org/tracker/CVE-2026-56211

https://security-tracker.debian.org/tracker/source-package/aom

Plugin Details

Severity: High

ID: 332088

File Name: debian_DSA-6411.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/5/2026

Updated: 8/5/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

Percentile: 57.62

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-56209

CVSS v3

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-56208

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:aom-tools, p-cpe:/a:debian:debian_linux:libaom-dev, p-cpe:/a:debian:debian_linux:libaom-doc, p-cpe:/a:debian:debian_linux:libaom3

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/5/2026

Vulnerability Publication Date: 6/19/2026

Reference Information

CVE: CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211