Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F174579403
D57843.id180621.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
1 KB
Referenced Files
None
Subscribers
None
D57843.id180621.diff
View Options
diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,35 @@
+ <vuln vid="ba8d239f-709f-11f1-a30e-28d2443e6cfa">
+ <topic>FFmpeg -- Out-of-bounds write</topic>
+ <affects>
+ <package>
+ <name>FFmpeg</name>
+ <range><lt>8.1.2</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159 reports:</p>
+ <blockquote cite="https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159">
+ <p>An out-of-bounds write vulnerability in FFmpeg's libavcodec library,
+specifically in the MagicYUV decoder, allows denial-of-service and,
+in some cases, can be exploited for remote code execution.
+
+This vulnerability is associated with the file libavcodec/magicyuv.C.
+This issue affects FFmpeg before version 8.1.2.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2026-8461</cvename>
+ <url>https://nvd.nist.gov/vuln/detail/CVE-2026-8461</url>
+ <url>https://github.com/advisories/GHSA-qff7-4q6c-m8h6</url>
+ </references>
+ <dates>
+ <discovery>2026-06-18</discovery>
+ <entry>2026-06-25</entry>
+ </dates>
+ </vuln>
+
<vuln vid="6a472f75-6fdc-11f1-bc26-8447094a420f">
<topic>go-git -- DoS vulnerability</topic>
<affects>
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Mon, Oct 5, 9:03 AM (4 h, 15 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
40233996
Default Alt Text
D57843.id180621.diff (1 KB)
Attached To
Mode
D57843: security/vuxml: document ffmpeg vulnerability
Attached
Detach File
Event Timeline
Log In to Comment