CVE-2026-58049: Ffmpeg
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.
Affected products
- Ffmpeg Ffmpeg
- Red Hat Red Hat Ai Inference Server
- Red Hat Red Hat Enterprise Linux Ai 3.0 For Rhel 9: before 0:6.1.6-3.el9ai (fixed in 0:6.1.6-3.el9ai)
- Red Hat Red Hat Enterprise Linux Ai 3.2 For Rhel 9: before 0:6.1.6-3.el9ai (fixed in 0:6.1.6-3.el9ai)
- Red Hat Red Hat Enterprise Linux Ai 3.3 For Rhel 9: before 0:6.1.6-3.el9ai (fixed in 0:6.1.6-3.el9ai)
- Red Hat Red Hat Enterprise Linux Ai 3.5 For Rhel 9: before 0:6.1.6-1.el9ai (fixed in 0:6.1.6-1.el9ai)
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
- Red Hat Red Hat Openshift Ai 3.4: before 1786611800 (fixed in 1786611800); before 1787076778 (fixed in 1787076778); before 1787077779 (fixed in 1787077779); before 1787076481 (fixed in 1787076481)
- Red Hat Red Hat Openshift Ai Rhoai
Published 2026-06-28. Last modified 2026-09-01.