CVE-2026-8461
FFmpeg FFmpeg, Red Hat Enterprise Linux AI 3.5 for RHEL 9, Red Hat AI Inference Server
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
- CVSS
- 8.8
- EPSS
- 0.48% 38.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18