• News/
  • bleepingcomputer-20260622210501

FFmpeg fixes PixelSmash flaw in widely used video decoder

BleepingComputer
·
Bill Toulas
·
Published Jun 22, 2026
·
Updated

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service  condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The vulnerability is tracked as CVE-2026-8461 and is a heap out-of-bounds write in the MagicYUV decoder. It received a high-severity score of 8.8 and can be leveraged via a malicious video file in AVI, MKV, or MOV format. Any application that uses libavcodec, FFmpeg’s core library for video decoding and encoding, is considered vulnerable. However, exploitation for remote code execution (RCE) is possible if the Address Space Layout Randomization (ASLR) defense is disabled or by chaining another vulnerability to defeat the protection. Researchers at software supply-chain security company JFrog say that PixelSmash stems from the way MagicYUV processes slices, independent regions of a video frame that can be decoded separately from the rest of the image. "The vulnerability is a one-row heap buffer overflow in the MagicYUV decoder’s slice handling, caused by an inconsistency between how the frame allocator and the decoder compute chroma plane heights," JFrog explains. PixelSmash can be triggered when the user opens AVI, MKV, or MOV video files, browses a directory containing the file (via thumbnail generation), or runs any automated media ingestion workflow. JFrog found that multiple popular media applications, such as ...

Read full article

Affected Software

17 affected components
FFmpeg Project libavcodec<8.1.2
FFmpeg Project MagicYUV decoder<8.1.2
FFmpeg Project FlashSV decoder<8.1.2
Jellyfin Jellyfin=10.11.9
Kodi Kodi
Emby Emby
Nextcloud Nextcloud
PhotoPrism PhotoPrism
OBS Project OBS Studio
Plex Plex
Slack Slack
Discord Discord
Telegram Telegram
WhatsApp WhatsApp
Gnome thumbnail generator
KDE thumbnail generator
Xfce thumbnail generator
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary vulnerability discussed in the article?

The article discusses a vulnerability in FFmpeg called 'PixelSmash' that can lead to remote code execution or denial-of-service conditions.

2

Which applications are impacted by the PixelSmash vulnerability?

The vulnerability affects applications such as Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

3

What is the potential impact of exploiting the PixelSmash flaw?

Exploitation of the PixelSmash flaw could result in remote code execution on Jellyfin servers and denial-of-service conditions in various applications.

4

How is the PixelSmash vulnerability categorized?

The PixelSmash vulnerability is tracked as CVE-… and is listed as exploited under KEV.

5

When was the PixelSmash vulnerability disclosed and fixed?

The vulnerability was disclosed and fixed on June 22, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203