L K via plug on 23 Jun 2026 08:06:51 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Critical FFmpeg flaw discovered


😲

On Tue, Jun 23, 2026, 8:38 AM jeffv via plug <plug@lists.phillylinux.org> wrote:
Critical FFmpeg flaw discovered: just watching a video can fully
compromise your system

https://cybernews.com/security/critical-ffmpeg-vulnerability-enables-complete-compromise/


Open a sketchy video file in VLC, stream it using Jellyfin or Kodi, or
don’t even open it at all – simply storing it can get you compromised
when the Linux file manager generates a thumbnail. A critical bug in
FFmpeg, a massively popular open-source video processing engine, allows
attackers to crash systems with ease and, in the worst cases, run
malicious code.

FFmpeg has released a new version, 8.1.2, with an urgent patch for a
critical vulnerability in its MagicYUV lossless video codec decoder. The
heap out-of-bounds write bug has a severity score of 8.8 out of 10 and
is tracked as CVE-2026-8461.
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug