Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58049

Опубликовано: 28 июн. 2026
Источник: nvd
CVSS3: 8.6
CVSS3: 7.6
EPSS Низкий

Описание

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.

EPSS

Процентиль: 14%
0.00227
Низкий

8.6 High

CVSS3

7.6 High

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.

CVSS3: 7.6
redhat
около 1 месяца назад

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.

CVSS3: 8.6
debian
около 1 месяца назад

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) perform ...

CVSS3: 8.6
github
около 1 месяца назад

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.

CVSS3: 8.6
fstec
около 1 месяца назад

Уязвимость функции decode_dlta() файла libavcodec/rasc.c видеодекодера RASC мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00227
Низкий

8.6 High

CVSS3

7.6 High

CVSS3

Дефекты

CWE-787
CWE-787