High severity8.8NVD Advisory· Published Jun 18, 2026· Updated Jul 23, 2026
CVE-2026-8461
CVE-2026-8461
Description
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- Range: <8.1.2
- osv-coords9 versionspkg:apk/chainguard/ffmpeg-6pkg:apk/chainguard/ffmpeg-7.1pkg:apk/chainguard/ffmpeg-8.0pkg:apk/wolfi/ffmpeg-7.1pkg:apk/wolfi/ffmpeg-8.0pkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-8&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-9&distro=openSUSE%20Tumbleweed
< 6.1.6-r0+ 8 more
- (no CPE)range: < 6.1.6-r0
- (no CPE)range: < 7.1.5-r0
- (no CPE)range: < 8.0.3-r0
- (no CPE)range: < 7.1.5-r0
- (no CPE)range: < 8.0.3-r0
- (no CPE)range: < 4.4.8-2.1
- (no CPE)range: < 7.1.5-1.1
- (no CPE)range: < 8.1.2-2.1
- (no CPE)range: < 9.0.1-1.1
Patches
Vulnerability mechanics
References
5News mentions
5- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News · Jun 29, 2026
- PixelSmash flaw turns video files into attack toolsMalwarebytes Labs · Jun 24, 2026
- FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS AppliancesSecurityWeek · Jun 23, 2026
- Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media FilesCyber Security News · Jun 23, 2026
- FFmpeg fixes PixelSmash flaw in widely used video decoderBleepingComputer · Jun 22, 2026