CVE-2026-58049 is a memory corruption vulnerability in FFmpeg’s RASC video decoder, specifically in the decode_dlta() function in libavcodec/rasc.c. The flaw arises because the decoder performs 32-bit reads and writes at the current row cursor before enforcing the NEXT_LINE row-boundary check, and because the DLTA region is validated in pixel units rather than byte units. On PAL8 frames, this mismatch can allow a DLTA run to access several bytes beyond the allocated row buffer. A crafted media stream using the RASC FourCC can therefore trigger a bitstream-controlled out-of-bounds heap write together with an adjacent out-of-bounds read during decoding, resulting in heap memory corruption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A memory corruption vulnerability involving heap write/read in FFmpeg's RASC video decoder.
An out-of-bounds heap write and adjacent out-of-bounds read vulnerability in FFmpeg's RASC decoder (decode_dlta in libavcodec/rasc.c) that can be triggered by a crafted media stream, leading to memory corruption.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.