RHSA-2026:52833: Important: RHELAI 3.2 Backport fixes for CVE-2026-64835 and CVE-2026-58049
CVE-2026-64835 FFmpeg: Arbitrary code execution, information disclosure, ordenial of service via crafted ADX/AAX audio filesCVE-2026-58049 FFmpeg: Memory corruption via crafted RASC video stream
Other sources
Important: RHELAI 3.2 Backport fixes for CVE-2026-64835 and CVE-2026-58049
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ffmpegto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-debugsourceto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
FFmpegto a version that resolves this vulnerability.Patch CVE-2026-64835 - Upgrade
Upgrade
FFmpegto a version that resolves this vulnerability.Patch CVE-2026-58049
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52833?
The severity of RHSA-2026:52833 is classified as high with a score of 7.
How do I fix RHSA-2026:52833?
To fix RHSA-2026:52833, apply the backport fixes provided for CVE-2026-64835 and CVE-2026-58049 in Red Hat Enterprise Linux AI.
What vulnerabilities are addressed in RHSA-2026:52833?
RHSA-2026:52833 addresses vulnerabilities CVE-2026-64835 and CVE-2026-58049 in FFmpeg related to arbitrary code execution and memory corruption.
What software is affected by RHSA-2026:52833?
RHSA-2026:52833 affects Red Hat Enterprise Linux AI and various Red Hat FFmpeg packages.
What types of risks do CVE-2026-64835 and CVE-2026-58049 pose?
CVE-2026-64835 poses risks of arbitrary code execution and information disclosure, while CVE-2026-58049 leads to memory corruption issues.