PT-2026-53081 · FFmpeg+1 · Ffmpeg+1

·

CVE-2026-58049

·

Published

2026-06-28

·

Updated

2026-09-04

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to the latest patch
Description The RASC video decoder in libavcodec contains a flaw where the decode dlta() function in libavcodec/rasc.c performs 32-bit reads and writes at the row cursor before the NEXT LINE row-boundary check. Additionally, the DLTA region is validated in pixel units instead of byte units. This allows a DLTA run on a PAL8 frame to access bytes beyond the row allocation. A specially crafted media stream using the RASC FourCC can trigger a bitstream-controlled out-of-bounds heap write and an adjacent out-of-bounds read, resulting in memory corruption, denial of service, or potential arbitrary code execution.
Recommendations Update to the latest version.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08913
CVE-2026-58049
ECHO-D121-7767-849C
JLSEC-2026-1171
OESA-2026-3541
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OESA-2026-3545
OPENSUSE-SU-2026:11545-1
OPENSUSE-SU-2026:11563-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:11682-1
RHSA-2026:43711
RHSA-2026:51180
RHSA-2026:52832
RHSA-2026:52833

Affected Products

Ffmpeg
Red Os