CVE-2026-58049
EUVD-2026-3996928.06.2026, 02:16
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux AI 3.0 for RHEL 9 | 0:6.1.6-3.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.2 for RHEL 9 | 0:6.1.6-3.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.3 for RHEL 9 | 0:6.1.6-3.el9ai ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux AI 3.5 for RHEL 9 | 0:6.1.6-1.el9ai ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
Vulnerability Media Exposure
References