
PEACH
Un cadre d’isolation des locataires
CVE-2026-8461 is an out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically within the MagicYUV decoder (libavcodec/magicyuv.c). It allows remote attackers to cause denial-of-service and, in certain conditions, achieve remote code execution by convincing a user to open a crafted MagicYUV-encoded media file. The vulnerability affects all FFmpeg versions before 8.1.2 and was disclosed on June 18, 2026, with the CVE assigned by JFrog. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is an out-of-bounds write (CWE-787) in the MagicYUV video decoder within FFmpeg's libavcodec library. When processing a specially crafted MagicYUV-encoded media file, the decoder writes data beyond the bounds of an allocated buffer, corrupting adjacent memory. The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction (e.g., opening a malicious media file). A patch was submitted via FFmpeg's code review system (GitHub Advisory, FFmpeg PR).
Successful exploitation can result in denial-of-service through application crash, or in more severe cases, arbitrary code execution with the privileges of the FFmpeg process. An attacker who achieves code execution could access sensitive data, modify files, or use the compromised process as a foothold for lateral movement within the affected environment. All three security dimensions — confidentiality, integrity, and availability — are rated High (GitHub Advisory).
libavcodec/magicyuv.c when decoded by a vulnerable FFmpeg version (before 8.1.2).SIGSEGV, SIGABRT) originating from libavcodec/magicyuv.c or related stack frames..mkv, .avi, or other containers) received from untrusted sources in media processing directories.The primary remediation is to upgrade FFmpeg to version 8.1.2 or later, which contains the fix for this vulnerability (GitHub Advisory, FFmpeg PR). Until patching is feasible, organizations should implement input validation to reject untrusted or unexpected MagicYUV-encoded media files, restrict FFmpeg usage to trusted media sources only, and run FFmpeg processes under least-privilege accounts to limit the blast radius of any successful exploitation.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."