CVE-2026-8461: Ffmpeg
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
Affected products
- Ffmpeg Ffmpeg: before 8.1.2 (fixed in 8.1.2)
- Red Hat Red Hat Ai Inference Server
- Red Hat Red Hat Enterprise Linux Ai 3.5 For Rhel 9: before 0:6.1.6-1.el9ai (fixed in 0:6.1.6-1.el9ai)
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
- Red Hat Red Hat Openshift Ai Rhoai
Published 2026-06-18. Last modified 2026-07-23.