Red Hat Patches Eight FFmpeg Flaws Bundled Inside RHEL AI 3 Runtime Images
Red Hat has published errata RHSA-2026:74089, a Moderate-rated security advisory that refreshes the FFmpeg multimedia stack shipped inside Red Hat Enterprise Linux AI 3.0. The update addresses eight separate CVEs — CVE-2026-8461, CVE-2026-40962, CVE-2026-58049, CVE-2026-64830, CVE-2026-64834, CVE-2026-64835, CVE-2026-66036 and CVE-2026-66039 — all of which were flagged by internal AIPCC security alerting against the 3.0 release of the platform base images, and all of which are listed with a severity level of Important or higher. Affected builds cover all four supported architectures: x86_64, s390x, ppc64le and aarch64. The fixed package set is ffmpeg-6.1.6-9.el9ai, which includes the ffmpeg-free-rhai binaries and the full family of shared libraries that AI workloads lean on, among them libavcodec-free-rhai, libavformat-free-rhai, libavfilter-free-rhai, libavutil-free-rhai, libswscale-free-rhai, libswresample-free-rhai and libpostproc-free-rhai. Red Hat stresses that these RPMs are internal build artefacts and are supported only as part of the Red Hat AI application platform, not as standalone packages.
The advisory does not publish exploitation details, proof-of-concept code, or a technical write-up of the individual defects, and no CVSS vectors or attack narratives are included in the errata text. What is known is the exposure surface rather than the exploit chain: FFmpeg libraries parse untrusted audio, video and image containers, and in a RHEL AI deployment those parsers typically sit behind data-ingestion and multimodal inference pipelines that accept files from users or from external datasets. Historically, defects in these demuxing and decoding paths are reached by feeding a malformed media file to a process that links the affected library, meaning the risk tracks wherever media is decoded rather than wherever ffmpeg is invoked interactively. Red Hat lists no additional mitigation or workaround for this errata — the Fixes field is empty — so the corrected package build is the sole remedy on offer. The advisory also notes that previously released errata relevant to the system are expected to be in place before this one is layered on.
The practical significance of this update is its reach. Because the vulnerable libraries are baked into RHEL AI 3.0 base images, exposure propagates to every container, model-serving pod and fine-tuning job built from those images, and affected components can persist in registries and derived images long after the host RPMs are refreshed. Media parsing libraries are an attractive target precisely because they sit at the boundary where untrusted external input first meets native code, and the potential consequences of this class of defect span process crashes, service disruption of inference endpoints, and in the worse cases memory corruption inside the decoding process. On current exploitation status, FIRST EPSS estimates the probability of exploitation activity in the next 30 days at 1.0 percent for CVE-2026-8461, 0.7 percent for CVE-2026-64834, 0.6 percent for CVE-2026-64830, 0.5 percent each for CVE-2026-58049, CVE-2026-64835 and CVE-2026-66036, 0.4 percent for CVE-2026-66039 and 0.2 percent for CVE-2026-40962. None of the eight CVEs appears in the CISA Known Exploited Vulnerabilities catalogue, and the errata itself describes no exploitation, which is a statement about what is currently observable rather than an assurance that these defects cannot be reached in a given RHEL AI deployment.
Attack Surface
Server OS, Supply Chain (Third-party vendors), Infrastructure
Tactics
Execution, Impact
Techniques
- T1203 – Exploitation for Client Execution
- T1499.004 – Application or System Exploitation
- T1195.002 – Compromise Software Supply Chain
SuperPRO's Threat Countermeasures Procedures
- Apply errata RHSA-2026:74089 and move all Red Hat Enterprise Linux AI 3.0 hosts to ffmpeg-6.1.6-9.el9ai on x86_64, s390x, ppc64le and aarch64, which remediates CVE-2026-8461, CVE-2026-40962, CVE-2026-58049, CVE-2026-64830, CVE-2026-64834, CVE-2026-64835, CVE-2026-66036 and CVE-2026-66039.
- Confirm that every previously released RHEL AI 3.0 errata has been installed before layering this update, following the procedure in Red Hat KB article 11258 (https://access.redhat.com/articles/11258), as the advisory makes this a prerequisite.
- Run the Red Hat Insights patch analysis service against the RHEL AI estate to enumerate systems still reporting vulnerable ffmpeg-free-rhai builds instead of relying on manual host lists.
- Validate package integrity after download against the published hashes, for example SRPM ffmpeg-6.1.6-9.el9ai.src.rpm SHA-256 fd31b72c36ade81c09a2b1f5e56eff6f8761e42b80bbdb5831b67eaf6ec46589 and ffmpeg-free-rhai-6.1.6-9.el9ai.x86_64.rpm SHA-256 cd24a91037cbbdc29277a574666fc5e49dcfd582afd63f6f6fe0099ea1470c36.
- Scan the container registry for RHEL AI 3.0 base images and any derived model-serving or fine-tuning images that still bundle libavcodec-free-rhai, libavformat-free-rhai, libavfilter-free-rhai, libavutil-free-rhai, libswscale-free-rhai, libswresample-free-rhai or libpostproc-free-rhai below 6.1.6-9.el9ai, and rebuild them.
- Verify remediation on each Red Hat Enterprise Linux AI 3.0 host with rpm -q ffmpeg-free-rhai libavcodec-free-rhai libavformat-free-rhai and confirm the reported build is 6.1.6-9.el9ai or later, since Red Hat lists no workaround for RHSA-2026:74089 and the corrected package build is the only remedy offered.
- Restart or redeploy RHEL AI 3.0 workloads that still have pre-6.1.6-9.el9ai libav* shared libraries mapped after the RPM transaction, and keep ffmpeg-free-rhai and its libraries consumed only as part of the Red Hat AI application platform, which Red Hat states is the sole supported use of these internal build artefacts.