8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
Basic Information
ID
CVE-2026-8461
Source
JFROG
Published
Jun 18, 2026 at 11:29
Modified
Jun 19, 2026 at 03:55
Affected Product
Vendor
FFmpeg
Product
FFmpeg
Affected Versions
FFmpeg FFmpeg 0