FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg存在安全漏洞,该漏洞源于RASC视频解码器的decode_move()函数中存在释放后重用,攻击者可以通过提供特制AVI文件,导致拒绝服务(崩溃)。以下版本受到影响:Red Hat Enterprise Linux AI (RHEL AI) 3版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | any |
affected |
any |
unaffected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat OpenShift AI (RHOAI) | any |
unaffected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56208 | 7.6 HIGH | Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode |
| CVE-2026-56209 | 7.1 HIGH | Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map p |
| CVE-2026-56210 | 7.1 HIGH | Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id |
| CVE-2026-56211 | 7.1 HIGH | Libaom: libaom: remote code execution via svc layer context handling with attacker-control |
| CVE-2026-12726 | 6.3 MEDIUM | Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses |
No comments yet