CVE Tools
Back to feed
Patch released FFmpeg rce libavcodec web-app

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

A heap out-of-bounds write in FFmpeg’s libavcodec MagicYUV decoder, tracked as CVE-2026-8461 (CVSS 8.8), can allow attackers to crash applications and potentially execute arbitrary code using specially crafted video files. JFrog describes the PixelSmash flaw as stemming from a mismatch in how the frame allocator and decoder calculate chroma plane heights, and notes that exploitation can be tailored to target FFmpeg’s AVBuffer refcounted buffer handling. Fixed in FFmpeg version 8.1.2, the issue affects a wide range of media players and servers that decode videos with FFmpeg, including Kodi, mpv, ffmpegthumbnailer, Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio—so updating promptly matters.