REDHAT-BUG-2490308: High severity FFmpeg libavcodec (MagicYUV decoder) vulnerability
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FFmpeg (libavcodec/magicyuv.C)to a version that resolves this vulnerability.Fixed in 8.1.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2490308?
The severity of REDHAT-BUG-2490308 is classified as high with a rating of 7.
What is the impact of REDHAT-BUG-2490308?
REDHAT-BUG-2490308 can lead to denial-of-service and potentially remote code execution.
How do I fix REDHAT-BUG-2490308?
To fix REDHAT-BUG-2490308, upgrade to a version of FFmpeg that addresses this vulnerability.
Which library is affected by REDHAT-BUG-2490308?
The vulnerability REDHAT-BUG-2490308 affects the libavcodec library in FFmpeg, specifically the MagicYUV decoder.
When was REDHAT-BUG-2490308 published?
REDHAT-BUG-2490308 was published on June 18, 2026.