CVE-2026-8461: Ffmpeg

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

Affected products

  • Ffmpeg Ffmpeg: before 8.1.2 (fixed in 8.1.2)
  • Red Hat Red Hat Ai Inference Server
  • Red Hat Red Hat Enterprise Linux Ai 3.5 For Rhel 9: before 0:6.1.6-1.el9ai (fixed in 0:6.1.6-1.el9ai)
  • Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
  • Red Hat Red Hat Openshift Ai Rhoai

Published 2026-06-18. Last modified 2026-07-23.