CVE-2026-56942: High severity vulnerability
Published Sep 15, 2026
In ReadTileInfo of vp9hwdheaders.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Frequently Asked Questions
1
Does an attacker need to be authenticated or interact with a user to exploit this issue?
The CVSS vector indicates that the attacker needs low-level privileges (PR:L). No user interaction is required (UI:N).
2
What level of access could exploitation provide?
The issue may allow remote escalation of privilege without requiring additional execution privileges. The CVSS assessment rates confidentiality, integrity, and availability impact as high.