CVE-2026-21069: Medium severity VC1 codec in libsavsvc.so vulnerability
Published Aug 10, 2026
·Updated
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Affected Software
1 affected component
VC1 codec in libsavsvc.so<SMR Aug-2026 Release 1
Event History
Aug 10, 2026
CVE Published
via MITRE·07:41 AM
Data Sourced
via MITRE·07:41 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-21069?
The severity of CVE-2026-21069 is rated as risk 41.
2
What types of attacks are possible with CVE-2026-21069?
CVE-2026-21069 allows local attackers to write out-of-bounds memory due to incorrect numeric type conversion.
3
Which software is affected by CVE-2026-21069?
CVE-2026-21069 affects the VC1 codec in libsavsvc.so.
4
How do I fix CVE-2026-21069?
To mitigate CVE-2026-21069, ensure that you update to the SMR Aug-2026 Release 1 or later.
5
What is the impact of CVE-2026-21069?
The impact of CVE-2026-21069 includes the potential for local attackers to exploit out-of-bounds memory writes.