RHSA-2026:51180: Important: Backport fixes for CVE-2026-64835 and CVE-2026-58049
CVE-2026-64835 FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio filesCVE-2026-58049 FFmpeg: Memory corruption via crafted RASC video stream
Other sources
Important: Backport fixes for CVE-2026-64835 and CVE-2026-58049
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ffmpegto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-debugsourceto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/ffmpeg-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavcodec-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavdevice-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavfilter-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavformat-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libavutil-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libpostproc-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswresample-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhaito a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-debuginfoto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
redhat/libswscale-free-rhai-develto a version that resolves this vulnerability.Fixed in 6.1.6-3.el9a - Upgrade
Upgrade
ffmpeg-6.1.6-3.el9aito a version that resolves this vulnerability.Patch CVE-2026-64835 - Upgrade
Upgrade
ffmpeg-6.1.6-3.el9aito a version that resolves this vulnerability.Patch CVE-2026-58049