RHSA-2026:60334HighCVSS 8.8

Red Hat Security Advisory: RHEL AI 3.4 RPM runtime CVE fix - ffmpeg

Published
August 26, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-64834 — FFmpeg: Denial of Service via crafted RTP/ASF stream CVE-2026-66036 — ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter CVE-2026-66039 — ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file

🎯 Affected products118

  • Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-0:6.1.6-7.el9ai.src as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-7.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-7.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-7.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-7.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.4 for RHEL 9
  • +88 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to applications utilizing FFmpeg for RTP/ASF stream demuxing, ensuring only trusted sources can provide such streams. Implement firewall rules to limit inbound connections to the affected services. This may impact legitimate functionality if trusted sources are inadvertently blocked.

🔗 References (4)