An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
https://github.com/the-artist111/NeuralReaper
https://github.com/ray-goldman/ffmpeg-jellyfix
https://github.com/0xBlackash/CVE-2026-8461
https://github.com/HORKimhab/CVE-2026-8461
https://github.com/patissierMongs/advisory-platform
https://github.com/Unclecheng-li/poc-lab
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json
https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159
https://bugzilla.redhat.com/show_bug.cgi?id=2490308