logo

FFmpeg fixes PixelSmash flaw in widely used video decoder

ID: b1aa83d0-d6c7-5e2c-86e3-89ca06ebf6ea

STIX ID: report--b1aa83d0-d6c7-5e2c-86e3-89ca06ebf6ea

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Bill Toulas

...
...

A high-severity heap out-of-bounds vulnerability (CVE-2026-8461, "PixelSmash") in FFmpeg's MagicYUV decoder can crash many media applications and—if ASLR is disabled or when chained with another bug—enable remote code execution; researchers demonstrated RCE against Jellyfin, numerous projects that use libavcodec are exposed, and FFmpeg 8.1.2 and vendor mitigations have been issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.