RHSA-2026:60335: Important: RHEL AI 3.5 RPM runtime CVE fix - ffmpeg
Important: RHEL AI 3.5 RPM runtime CVE fix - ffmpeg
Other sources
RPM packages are internal build artifacts and not supported on their own. They are only supported as part of the Red Hat AI application platform.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ffmpegto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/ffmpeg-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/ffmpeg-debugsourceto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-7.el9a
Event History
Frequently Asked Questions
Which deployments should treat these packages as supported and in scope for remediation?
The affected RPM packages are supported only when used as part of the Red Hat AI application platform. They are internal build artifacts and are not supported on their own.
Which package variants are covered by this advisory?
The listed components are redhat/ffmpeg, redhat/ffmpeg-debuginfo, redhat/ffmpeg-debugsource, redhat/ffmpeg-free-rhai, redhat/ffmpeg-free-rhai-debuginfo, redhat/ffmpeg-free-rhai-devel, and redhat/libavcodec-free-rhai.