
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-8461 is an out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically within the MagicYUV decoder (libavcodec/magicyuv.c). It allows remote attackers to cause denial-of-service and, in certain conditions, achieve remote code execution by convincing a user to open a crafted MagicYUV-encoded media file. The vulnerability affects all FFmpeg versions before 8.1.2 and was disclosed on June 18, 2026, with the CVE assigned by JFrog. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is an out-of-bounds write (CWE-787) in the MagicYUV video decoder within FFmpeg's libavcodec library. When processing a specially crafted MagicYUV-encoded media file, the decoder writes data beyond the bounds of an allocated buffer, corrupting adjacent memory. The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction (e.g., opening a malicious media file). A patch was submitted via FFmpeg's code review system (GitHub Advisory, FFmpeg PR).
Successful exploitation can result in denial-of-service through application crash, or in more severe cases, arbitrary code execution with the privileges of the FFmpeg process. An attacker who achieves code execution could access sensitive data, modify files, or use the compromised process as a foothold for lateral movement within the affected environment. All three security dimensions — confidentiality, integrity, and availability — are rated High (GitHub Advisory).
libavcodec/magicyuv.c when decoded by a vulnerable FFmpeg version (before 8.1.2).SIGSEGV, SIGABRT) originating from libavcodec/magicyuv.c or related stack frames..mkv, .avi, or other containers) received from untrusted sources in media processing directories.The primary remediation is to upgrade FFmpeg to version 8.1.2 or later, which contains the fix for this vulnerability (GitHub Advisory, FFmpeg PR). Until patching is feasible, organizations should implement input validation to reject untrusted or unexpected MagicYUV-encoded media files, restrict FFmpeg usage to trusted media sources only, and run FFmpeg processes under least-privilege accounts to limit the blast radius of any successful exploitation.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"