INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FFmpeg fixes PixelSmash flaw in widely used video decoder

| 2026-06-24 17:23 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A critical vulnerability, PixelSmash, has been discovered in FFmpeg's MagicYUV video decoder, allowing attackers to turn a tiny, malformed video into an attack tool. The vulnerability, tracked as CVE-2026-8461 with a CVSS score of 8.8, affects tens of millions of Linux systems that rely on ffmpegthumbnailer and system libavcodec for thumbnails, potentially triggering denial of service (DoS) or targeted remote code execution (RCE) attacks when a malicious file is present. The vulnerability can be triggered by crafting a specially formatted AVI, MKV, or MOV file, which requires an application using FFmpeg to process untrusted media and have the MagicYUV decoder compiled in. As of now, Jellyfin and Nextcloud servers with at least tens of thousands of active internet-reachable servers are vulnerable, while consumer network attached storage (NAS) and smart TV platforms that use FFmpeg for previews and thumbnails may also be affected due to their widespread deployment.
Technical Mitigations AI-generated
• Update FFmpeg to version 8.1.2 or later, which includes a fix for CVE-2026-8461. • Check if MagicYUV is enabled and disable it or apply patches where possible in affected systems. • Reduce automatic processing of untrusted video by reviewing preview providers and thumbnailers, especially for rarely used formats. • Monitor abnormal crashes of media players, thumbnailers, or media servers, particularly those using FFmpeg.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

av•••••.free
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-8461CVE-2026-8461
Target & Sectors
Global Scope
Incident Timeline
‎2026/06/24
Researchers at JFrog discovered a critical vulnerability, PixelSmash (CVE-2026-8461), in FFmpeg's MagicYUV video decoder that can be exploited for remote code execution on vulnerable media servers.
infrastructure Linux
infrastructure 8.1.2
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎8.1.2
Software Version
Intelligence Sources
BleepingComputer 2026-06-22
Malware Bytes 2026-06-24