threat-intel
FFmpeg fixes PixelSmash flaw in widely used video decoder
High
Summary
A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the decoder’s slice handling, primarily affecting media applications like Jellyfin, Kodi, and OBS Studio. The vulnerability highlights a significant supply-chain risk due to the widespread use of FFmpeg and the potential for attackers to exploit this weakness through crafted video files or automated workflows.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data