Skip to content
Red HatCVE-2026-18393

Red Hat FFmpeg: denial of service

Medium5.4CVE-2026-18393 · Published Aug 28, 2026

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux AI (RHEL AI) 3
Product
all versionsNo fix yet
Red Hat OpenShift AI (RHOAI)
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat file-psd plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat libsolv: denial of service
Medium5.5Aug 28
Red Hat file-ico plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat file-pvr plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat GIMP: denial of service
Medium6.1Aug 28
Red Hat Ansible Automation Platform 2: resource exhaustion
Medium5.9Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.