THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-58049 (HIGH 8.6) — FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the

[NVD] CVE-2026-58049 (HIGH 8.6) — FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the

lownvdPublished 2026-06-28

CVE-2026-58049 CVSS: 8.6 HIGH Published: 2026-06-28T02:16:30.477

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58049