VYPR

ffmpeg

by Debian

CVEs (1)

  • CVE-2026-58049Jun 29, 2026
    risk 0.00cvss epss 0.00

    FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past…