Unrated severityNVD Advisory· Published Jun 18, 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
CVE-2026-8461
Description
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versions
< 8.0.3-r0+ 1 more
- (no CPE)range: < 8.0.3-r0
- (no CPE)range: < 8.0.3-r0
Patches
Vulnerability mechanics
References
1News mentions
5- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News · Jun 29, 2026
- PixelSmash flaw turns video files into attack toolsMalwarebytes Labs · Jun 24, 2026
- FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS AppliancesSecurityWeek · Jun 23, 2026
- Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media FilesCyber Security News · Jun 23, 2026
- FFmpeg fixes PixelSmash flaw in widely used video decoderBleepingComputer · Jun 22, 2026