RHSA-2026:52832: Important: RHELAI 3.0 Backport fixes for CVE-2026-64835 and CVE-2026-58049
CVE-2026-64835 FFmpeg: Arbitrary code execution, information disclosure, ordenial of service via crafted ADX/AAX audio filesCVE-2026-58049 FFmpeg: Memory corruption via crafted RASC video stream
Other sources
Important: RHELAI 3.0 Backport fixes for CVE-2026-64835 and CVE-2026-58049
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ffmpegto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-debugsourceto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52832?
The severity of RHSA-2026:52832 is classified as high with a severity score of 7.
What vulnerabilities are addressed by RHSA-2026:52832?
RHSA-2026:52832 addresses CVE-2026-64835 related to FFmpeg arbitrary code execution and CVE-2026-58049 concerning memory corruption.
How do I fix RHSA-2026:52832?
To fix RHSA-2026:52832, update your Red Hat Enterprise Linux AI system to the latest package versions that include the backport fixes.
What software does RHSA-2026:52832 affect?
RHSA-2026:52832 affects multiple components including redhat/ffmpeg and associated debug packages in Red Hat Enterprise Linux AI.
What risks are associated with RHSA-2026:52832?
The risks associated with RHSA-2026:52832 include arbitrary code execution, information disclosure, and denial of service through crafted media files.