The vendor explicitly identifies these products as affected by this CVE.
- ffmpeg.src as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-aws-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-azure-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-azure-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-gcp-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhoai/odh-vllm-gaudi-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in FFmpeg. An attacker could exploit a signed integer overflow vulnerability within the DVB subtitle parser by providing a specially crafted WTV (Windows Recorded TV Show) file. This overflow can lead to a heap buffer overflow, enabling out-of-bounds memory writes. The consequence of this vulnerability is potential memory corruption or arbitrary code execution.
- Remediation
- To mitigate this issue, avoid processing untrusted WTV (Windows Recorded TV Show) files, especially those containing DVB subtitles. Exercise caution when handling multimedia files from unknown or suspicious sources.
