An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.
This vulnerability is associated with the file libavcodec/magicyuv.C.
This issue affects FFmpeg before version 8.1.2.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg | Jun 29, 2026 | Jun 18, 2026 |
| Debian | — | Upgrade ffmpeg | Jul 23, 2026 | Jul 23, 2026 |
| Ffmpeg | — | Upgrade to FFmpeg version 8.1.2Upgrade to FFmpeg version 8.0.3Upgrade to FFmpeg version 9.0 | Jun 22, 2026 | Jun 18, 2026 |
| Freebsd | — | Upgrade ffmpeg6Upgrade ffmpeg4Upgrade ffmpeg | Jun 30, 2026 | Jun 25, 2026 |
| Ubuntu | — | Upgrade libavformat58 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavformat-extra58 (Ubuntu Pro)Upgrade libavfilter7 (Ubuntu Pro)Upgrade libavcodec58 (Ubuntu Pro)Upgrade libavcodec-extra58 (Ubuntu Pro) | Sep 14, 2026 | Sep 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub