CVE-2026-8461
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
Description
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
In plain language
AI Worth attentionCVE-2026-8461 is a FFmpeg weakness in the MagicYUV decoder that can crash (and sometimes allow code execution) when your software opens a specially crafted video file; if you process untrusted video from users or the internet, you should update to FFmpeg 8.1.2 soon.
In FFmpeg’s libavcodec MagicYUV decoder, a crafted video can trigger a heap out-of-bounds write via an unusual slice height, leading to denial-of-service and potentially remote code execution when applications process the file (network-delivered media; no authentication required).
What to do now
- Check whether your system uses a vulnerable FFmpeg version (any FFmpeg before 8.1.2) in the apps that decode AVI/MKV/MOV files.
- Identify which of those apps pass uploaded or internet-sourced media to FFmpeg’s libavcodec (MagicYUV decode path).
- Upgrade FFmpeg to 8.1.2 or later across every server/container where it’s used.
- If you can’t upgrade right away, block or quarantine untrusted uploaded media and disable automatic decoding for unknown file types until the update is applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and Moreen·The Hacker News·
- FFmpeg MagicYUV Vulnerability Exposes Media Applicationsen-us·Daily CyberSecurity (securityonline.info)· Patch FFmpeg rce
- В FFmpeg исправили RCE-уязвимость PixelSmashru-ru·Хакер (xakep.ru)· PoC FFmpeg rce
- FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliancesen-us·SecurityWeek· Patch FFmpeg rce
- FFmpeg fixes PixelSmash flaw in widely used video decoderen-us·BleepingComputer· Patch MagicYUV decoder supply-chain
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-8461 and every CVE in our database. Create a free account — no credit card required.
Create Free Account