PT-2026-50667 · FFmpeg · Ffmpeg

Published

2026-06-18

·

Updated

2026-06-23

·

CVE-2026-8461

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 8.1.2
Description An out-of-bounds write occurs in the libavcodec library, specifically within the MagicYUV decoder. This issue is triggered by an odd slice height and is associated with the file libavcodec/magicyuv.C. It can lead to a denial-of-service or potentially allow remote code execution.
Recommendations Update to version 8.1.2 or later.

Fix

RCE

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8461

Affected Products

Ffmpeg