CVE-2026-58049Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-28); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-06-28: 2Mentions · 2026-06-29: 2Mentions · 2026-07-05: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-28: 2Technical Details · 2026-06-29: 106-2806-2907-05
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-282
Disclosure1Patch1
2026-06-292
Disclosure1Patch1
2026-07-051
General1
Full discourse5 posts
  • Drets digitals@dretsdigitals
    Disclosure

    @OpenAI La investigació documentada en aquest repositori ha donat lloc a l'assignació de diversos identificadors internacionals de seguretat (CVE), com ara des del CVE-2026-58049 fins al CVE-2026-58058. Així que almenys en part el que troba és real i amb impacte.

    Post summary

    The message announces that a set of CVEs (CVE‑2026‑58049 to CVE‑2026‑58058) have been assigned following documented research, indicating these vulnerabilities are real and potentially impactful, but no technical or exploit details are given.

    1002049
    182 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-58049 Out-of-Bounds Heap Write in FFmpeg RASC Video Decoder libavcodec https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58049

    Post summary

    CVE-2026-58049 is an out‑of‑bounds heap write flaw in FFmpeg’s RASC Video Decoder, disclosed via vulmon.com without any PoC, exploit code, or mitigation guidance.

    00020137
    4.1K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 #CVE-2026-58049 & #CVE-2022-3109: Why Your #Linux Mint 22 FFmpeg Installation Is a Ticking Security Bomb—And How to Defuse It Before Attackers Strike + Video https://undercodetesting.com/cve-2026-58049-cve-2022-3109-why-your-linux-mint-22-ffmpeg-installation-is-a-ticking-security-bomb-and-how-to-defuse-it-before-attackers-strike-video/ Educational Purposes!

    Post summary

    This text advertises an article discussing CVE‑2026‑58049 and CVE‑2022‑3109 on Linux Mint 22 FFmpeg, but contains no technical, exploitation, or patch details.

    0000071
    650 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-58049 (CVSS 8.8) in FFmpeg RASC decoder. Assess FFmpeg usage and apply patches where deployed. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/9POqr4cS4L

    Post summary

    The post identifies CVE-2026-58049 affecting FFmpeg's RASC decoder, highlights its high CVSS score, and advises checking FFmpeg usage and applying available patches.

    0000062
    92 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - FFmpeg RASC Decoder Out-of-Bounds Heap Write (CVE-2026-58049) FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units. A crafted media stream can trigger a bitstream-controlled out-of-bounds heap write (and adjacent out-of-bounds read). Impact: Memory corruption, denial of service, or potential arbitrary code execution when decoding a malicious RASC file. 👉Affected: FFmpeg (versions prior to the latest patch) Action: Update FFmpeg to the latest version.

    Post summary

    High severity CVE‑2026‑58049 targets FFmpeg’s RASC decoder, enabling out‑of‑bounds heap writes that can lead to memory corruption. Users are urged to apply the latest patch to mitigate the risk.

    00000104
    232 followersView on X

Explore more