CVE-2026-8461
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
- Published
- Jun 18, 2026
- Updated
- Jul 23, 2026
- Assigning CNA
- JFROG
- Evidence observed
- Aug 6, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 73.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
Sources
3- CVE-2026-8461-EXPExploit
Proof-of-concept exploit for CVE-2026-8461, a heap out-of-bounds write in FFmpeg's MagicYUV decoder, achieving remote code execution via AVBuffer.free hijacking. Includes calibration scripts for debug and production builds.
- CVE-2026-8461Informational
CVE-2026-8461
Proof-of-concept exploit for CVE-2026-8461, generating a crafted AVI file that triggers a crash in unpatched ffmpeg versions.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.