The vendor explicitly identifies these products as affected by this CVE.
- ffmpeg.src as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhoai/odh-vllm-gaudi-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in FFmpeg's AV1 Real-time Transport Protocol (RTP) packetizer. A local attacker could entice a user to process a crafted AV1 input packet. This crafted packet could cause an out-of-bounds read, potentially leading to information disclosure or a denial of service (DoS) condition.
- Remediation
- No mitigation is currently available for this flaw.
