1 post
RowSpill (CVE-2026-58049): root-causing, scaling, and patching a heap out-of-bounds write that sat in FFmpeg's RASC DLTA decoder for eight years.