FFmpeg fixes PixelSmash RCE vulnerability
Summary
FFmpeg fixed a high-severity RCE vulnerability tracked as CVE-2026-8461 and related to the PixelSmash issue in libavcodec. The flaw affected MagicYUV handling in AVI, MKV, and MOV files and could impact software that relies on FFmpeg, including Jellyfin, Nextcloud, Kodi, mpv, Emby, and PhotoPrism. JFrog credited the discovery and noted that patched releases are available, including FFmpeg 8.1.2 and a Jellyfin update. The issue creates a clear security patching need for any vendor or platform embedding FFmpeg-based media processing.
Classifications
industries
No industries detected
applications
Accounting and Taxes
AskAI Classifications
Labels
DevOps Platform
Software Development Tools
Software Supply Chain Security
Linked Companies
JFrog Ltd
$100M to $250M