CVE Tools

FFmpeg fixes PixelSmash flaw in widely used video decoder

BleepingComputerBy Bill Toulas

PatchMagicYUV decoder

Our summary

FFmpeg has patched a newly reported “PixelSmash” issue (CVE-2026-8461), a heap out-of-bounds write in the MagicYUV decoder that can be triggered by specially crafted video files in AVI, MKV, or MOV formats. The flaw matters because it may lead to remote code execution on affected FFmpeg-based products under specific conditions (e.g., when ASLR is disabled or combined with other weaknesses), and it can also cause denial-of-service crashes; reported targets include Jellyfin and media software such as Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The fix is included in FFmpeg version 8.1.2, and anyone using libavcodec with MagicYUV support should update and assess exposure.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store