<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5" -->

---
title: FFmpeg fixes PixelSmash flaw in widely used video decoder
description: A heap out-of-bounds write vulnerability (CVE-2026-8461), dubbed &#x27;PixelSmash&#x27;, has been discovered in FFmpeg&#x27;s MagicYUV decoder. The flaw affects any...
canonical: https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: FFmpeg fixes PixelSmash flaw in widely used video decoder | daily.dev
og:description: A heap out-of-bounds write vulnerability (CVE-2026-8461), dubbed &#x27;PixelSmash&#x27;, has been discovered in FFmpeg&#x27;s MagicYUV decoder. The flaw affects any...
og:url: https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5
og:image: https://api.daily.dev/og/posts/3SxHPnzu5.png
og:image:alt: FFmpeg fixes PixelSmash flaw in widely used video decoder
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# FFmpeg fixes PixelSmash flaw in widely used video decoder

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 37 upvotes · 0 comments

## Summary

A heap out-of-bounds write vulnerability (CVE-2026-8461), dubbed 'PixelSmash', has been discovered in FFmpeg's MagicYUV decoder. The flaw affects any application using libavcodec, including Kodi, OBS Studio, Nextcloud, PhotoPrism, Emby, and Jellyfin. Researchers at JFrog demonstrated full RCE against a Jellyfin 10.11.9 server by dropping a crafted AVI file into its media library, which triggers an automatic ffprobe scan that fires the exploit. RCE requires ASLR to be disabled or chained with a separate info-disclosure bug; otherwise the flaw reliably causes denial-of-service. Plex is unaffected due to a custom FFmpeg build with a minimal decoder allowlist. FFmpeg 8.1.2 (released June 17) patches the issue. The vulnerability is considered a supply-chain risk because the MagicYUV decoder is embedded in hundreds of projects that trust FFmpeg to safely handle untrusted media input.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder>

## Similar posts on daily.dev

- [Hole in widely-used FFmpeg codec could crash media servers or enable RCE](https://daily.dev/posts/hole-in-widely-used-ffmpeg-codec-could-crash-media-servers-or-enable-rce-cflqjb7as) · CSO Online · 12 upvotes · 0 comments
- [PixelSmash – Critical FFmpeg Vulnerability Turns Media Files into Weapons](https://daily.dev/posts/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons-pieofxy5v) · JFrog · 3 upvotes · 0 comments
- [AI-Enabled Security Researchers Discover How a Crafted Video Can Provide Attackers Access to Your PC](https://daily.dev/posts/ai-enabled-security-researchers-discover-how-a-crafted-video-can-provide-attackers-access-to-your-pc-oeqkbxafa) · InfoQ · 1 upvotes · 0 comments

---

Tags: [#backend](https://daily.dev/tags/backend), [#jellyfin](https://daily.dev/tags/jellyfin), [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"FFmpeg fixes PixelSmash flaw in widely used video decoder","url":"https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5"},"datePublished":"2026-06-22T21:08:52.962Z","dateModified":"2026-07-02T02:14:49.155Z","description":"A heap out-of-bounds write vulnerability (CVE-2026-8461), dubbed 'PixelSmash', has been discovered in FFmpeg's MagicYUV decoder. The flaw affects any...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c42074143cbf23ba1a2485200eb7a63?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c42074143cbf23ba1a2485200eb7a63?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder-3sxhpnzu5","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":37},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"backend,jellyfin,security","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"FFmpeg fixes PixelSmash flaw in widely used video decoder"}]}
```

