RHSA-2026:74089MediumCVSS 8.8

Red Hat Security Advisory: RHEL AI 3.0 RPM runtime CVE fix - ffmpeg

Published
September 30, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-8461 — ffmpeg: FFmpeg: Remote code execution via out-of-bounds write in MagicYUV decoder CVE-2026-40962 — FFmpeg: FFmpeg: Integer overflow and out-of-bounds write via CENC subsample data CVE-2026-58049 — FFmpeg: FFmpeg: Memory corruption via crafted RASC video stream CVE-2026-64830 — ffmpeg: FFmpeg: Arbitrary code execution via heap buffer overflow in VobSub subtitle demuxer. CVE-2026-64834 — FFmpeg: Denial of Service via crafted RTP/ASF stream CVE-2026-64835 — FFmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files CVE-2026-66036 — ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter CVE-2026-66039 — ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file

🎯 Affected products118

  • Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-0:6.1.6-9.el9ai.src as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debuginfo-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-debugsource-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-debuginfo-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • ffmpeg-free-rhai-devel-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-9.el9ai.aarch64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-9.el9ai.ppc64le as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-9.el9ai.s390x as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • libavcodec-free-rhai-debuginfo-0:6.1.6-9.el9ai.x86_64 as a component of Red Hat Enterprise Linux AI 3.0 for RHEL 9
  • +88 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, avoid processing VobSub subtitle files from untrusted or unknown sources. For applications that utilize FFmpeg's VobSub demuxer, consider running them within a sandboxed environment to restrict the potential impact of a successful exploit. Workaround: To mitigate this issue, restrict network access to applications utilizing FFmpeg for RTP/ASF stream demuxing, ensuring only trusted sources can provide such streams. Implement firewall rules to limit inbound connections to the affected services. This may impact legitimate functionality if trusted sources are inadvertently blocked.

🔗 References (3)