FFmpeg fixes PixelSmash flaw in widely used video decoder
ID: b1aa83d0-d6c7-5e2c-86e3-89ca06ebf6ea
STIX ID: report--b1aa83d0-d6c7-5e2c-86e3-89ca06ebf6ea
Feed Name: Bleeping Computer
Threat Score
A high-severity heap out-of-bounds vulnerability (CVE-2026-8461, "PixelSmash") in FFmpeg's MagicYUV decoder can crash many media applications and—if ASLR is disabled or when chained with another bug—enable remote code execution; researchers demonstrated RCE against Jellyfin, numerous projects that use libavcodec are exposed, and FFmpeg 8.1.2 and vendor mitigations have been issued.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
