CVE-2026-64835
CVE-2026-64835: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh8.8
High [CVE-2026-64835] Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files
CVE-2026-64835Source published Source updated
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count. A flaw was found in FFmpeg. This could lead to the attacker triggering both out-of-bounds reads and writes, potentially resulting in arbitrary code execution, information disclosure, or denial of service. Conditions for…
- Affected products in this advisory
- Red Hat Enterprise Linux AI 3.0 for RHEL 9
- Red Hat Enterprise Linux AI 3.2 for RHEL 9
- Red Hat Enterprise Linux AI 3.3 for RHEL 9
- Red Hat AI Inference Server 3.2
3 more entries in the full advisory.
- Source-reported affected versions
- 8.1.2
- Source-reported fixed versions
- ffmpeg-0:6.1.6-3.el9ai
- rhaiis/vllm-cuda-rhel9:1787860580
- rhaiis/model-opt-cuda-rhel9:1787772157
- rhaiis/vllm-rocm-rhel9:1787884873
11 more entries in the full advisory.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.