---
id: CVE-2026-58049
title: >-
  FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit
  reads and writes at the row cursor before the NEXT_LINE row-boundary check and
  validates the DLTA region in pixel rather than byte units, so a DLTA run on a
  P…
summary: >-
  FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit
  reads and writes at the row cursor before the NEXT_LINE row-boundary check and
  validates the DLTA region in pixel rather than byte units, so a DLTA run on a
  P…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'
cwe:
  - CWE-787
published: '2026-06-28'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58049'
references:
  - url: 'https://github.com/FFmpeg/FFmpeg/blob/master/libavcodec/rasc.c'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/bikini/exploitarium/tree/main/ffmpeg-rasc-dlta-calc-poc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-rasc-decoder-decode-dlta
    label: disclosure@vulncheck.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:43711'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-58049'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2493952'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58049.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-58049'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58049'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52832'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52833'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51180'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61628'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61629'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68696'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68699'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68698'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68697'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00496
epssPercentile: 0.39926
ingestedAt: '2026-07-31T22:04:41.286Z'
vendor: Red Hat
product: Red Hat Enterprise Linux AI 3.0 for RHEL 9
affected:
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - enterprise_linux_ai_3_0_for_rhel 9
  - enterprise_linux_ai_3_2_for_rhel 9
  - enterprise_linux_ai_3_3_for_rhel 9
  - enterprise_linux_ai_3_5_for_rhel 9
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - openshift_ai 3.4
patched:
  - enterprise_linux_ai_3_0_for_rhel 9
  - enterprise_linux_ai_3_2_for_rhel 9
  - enterprise_linux_ai_3_3_for_rhel 9
  - enterprise_linux_ai_3_5_for_rhel 9
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - openshift_ai 3.4
scores:
  nvd: 8.6
  vendor: 7.6
---

## Overview

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:52832** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.0 for RHEL 9 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52832)
- **RHSA-2026:52833** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.2 for RHEL 9 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52833)
- **RHSA-2026:51180** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 for RHEL 9 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51180)
- **RHSA-2026:43711** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.5 for RHEL 9 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43711)
- **RHSA-2026:61628** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61628)
- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)
- **RHSA-2026:61629** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61629)
- **RHSA-2026:68696** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68696)
- **RHSA-2026:68699** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68699)
- **RHSA-2026:68698** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68698)
- **RHSA-2026:68697** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68697)
- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58049.json)
