CVE-2026-21091: Libcodec2secevrcdec.so vulnerability
Published Sep 9, 2026
·Updated
Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Affected Software
1 affected component
libcodec2secevrcdec.so<SMR Sep-2026 Release 1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libcodec2secevrcdec.soto a version that resolves this vulnerability.Fixed in SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as exploitable by local attackers, so an attacker needs local access to the affected device or an existing way to execute code locally.
2
What is the potential security impact?
Successful exploitation allows an attacker to write outside the intended memory bounds in libcodec2secevrcdec.so. The provided information does not state whether this can lead to code execution, privilege escalation, or denial of service.