The vendor explicitly identifies these products as affected by this CVE.
- ffmpeg.src as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhoai/odh-vllm-gaudi-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in FFmpeg. An incorrect integer narrowing conversion in the AV1 RTP packetizer can lead to an out-of-bounds memory access. This occurs when processing specially crafted AV1 RTP (Real-time Transport Protocol) packets, where a large OBU (Operating Block Unit) size is incorrectly handled due to a casting issue on certain platforms. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.
- Remediation
- No mitigation is currently available for this flaw.
