CVE-2026-8461: Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FFmpeg (libavcodec/magicyuv decoder)to a version that resolves this vulnerability.Fixed in 8.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8461?
CVE-2026-8461 has a severity rating of high at 8.8.
How do I fix CVE-2026-8461?
To fix CVE-2026-8461, update your FFmpeg to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-8461?
CVE-2026-8461 is a heap out-of-bounds write vulnerability in the MagicYUV decoder of FFmpeg.
What are the potential consequences of CVE-2026-8461?
Exploitation of CVE-2026-8461 can lead to denial-of-service and potentially remote code execution.
Which component of FFmpeg is affected by CVE-2026-8461?
CVE-2026-8461 affects the libavcodec library specifically in the MagicYUV decoder.