FFmpeg Fixes PixelSmash Flaw in Widely Used Video Decoder
ID: fb566d2a-38a2-5ebc-a858-79d6eebe36c5
STIX ID: report--fb566d2a-38a2-5ebc-a858-79d6eebe36c5
Feed Name: CosmicBytez Labs
Threat Score
FFmpeg released a patch for "PixelSmash" (CVE-2025-32956), a critical flaw in the video decoding pipeline that can cause heap corruption resulting in crashes (DoS) across many media applications and, under specific conditions, enable remote code execution—Jellyfin's transcoding path is especially at risk; maintainers are urged to update immediately or mitigate by disabling untrusted media sources, restricting uploads, isolating transcoding, and monitoring for crash loops.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
