We use cookies to help us improve our webpage. Please read our Cookie Policy .

AS-2026-015: FFmpeg

2026-08-03

Severity

Important

Status

Ongoing


Statement

FFmpeg announced multiple vulnerabilities that have been fixed in the latest release of FFmpeg.

CVE-2026-8461 affected ASUSTOR products with from ADM 4.1 to ADM 5.1.

  • FFmpeg 7.1.5 has been updated on ADM 5.1.4.RJV2 to resolve the issues.

Affected Products

Product Severity Fixed Release Availability
ADM 5.0 and 5.1 Important Upgrade to ADM 5.1.4.RJV2 or above.
ADM 4.3, 4.2 and 4.1 Important Ongoing

Detail

  • CVE-2026-8461
    • Severity: High
    • CVSS3.1 Base Score: 8.8
    • CVSS3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    • An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

Reference


Revision

Revision Date Description
1 2026-07-15 Initial public release.
2 2026-08-03 Release ADM 5.1.4.RJV2 and FFmpeg 7.1.5 for fixing the issues on ADM 5.0 and above.