{"id":"CVE-2026-58049","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-58049","summary":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region…","details":"FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.","published":"2026-06-28T02:16:30.477","modified":"2026-08-17T12:18:55.780","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FFmpeg/FFmpeg/blob/master/libavcodec/rasc.c"},{"type":"WEB","url":"https://github.com/bikini/exploitarium/tree/main/ffmpeg-rasc-dlta-calc-poc"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-rasc-decoder-decode-dlta"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:43711"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:51180"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:52832"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:52833"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-58049"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493952"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58049.json"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T12:18:55.780"}}