Open a sketchy video file in VLC, stream it using Jellyfin or Kodi, or don’t even open it at all – simply storing it can get you compromised when the Linux file manager generates a thumbnail.
I suppose someone's dvr can be compromised if they add a malicious mpeg that uses MagicYUV. Maybe quick fix is to just disable MagicYUV until you can test the new ffmpeg.