Heap buffer overflow in av1 encoder first-pass stats buffer via lap mode. (CVE-2026-56208) Arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack. (CVE-2026-56209) Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id. (CVE-2026-56210) Remote code execution via svc layer context handling with attacker-controlled frames. (CVE-2026-56211)