| jeffv via plug on 23 Jun 2026 05:38:57 -0700 |
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
| [PLUG] Critical FFmpeg flaw discovered |
https://cybernews.com/security/critical-ffmpeg-vulnerability-enables-complete-compromise/Open a sketchy video file in VLC, stream it using Jellyfin or Kodi, or don’t even open it at all – simply storing it can get you compromised when the Linux file manager generates a thumbnail. A critical bug in FFmpeg, a massively popular open-source video processing engine, allows attackers to crash systems with ease and, in the worst cases, run malicious code.
FFmpeg has released a new version, 8.1.2, with an urgent patch for a critical vulnerability in its MagicYUV lossless video codec decoder. The heap out-of-bounds write bug has a severity score of 8.8 out of 10 and is tracked as CVE-2026-8461.
___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug