FFmpeg fixes PixelSmash RCE vulnerability

General News

Summary

FFmpeg fixed a high-severity RCE vulnerability tracked as CVE-2026-8461 and related to the PixelSmash issue in libavcodec. The flaw affected MagicYUV handling in AVI, MKV, and MOV files and could impact software that relies on FFmpeg, including Jellyfin, Nextcloud, Kodi, mpv, Emby, and PhotoPrism. JFrog credited the discovery and noted that patched releases are available, including FFmpeg 8.1.2 and a Jellyfin update. The issue creates a clear security patching need for any vendor or platform embedding FFmpeg-based media processing.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AI Classifications

Labels
DevOps Platform Software Development Tools Software Supply Chain Security

Linked Companies

JFrog Ltd
$100M to $250M