FFmpeg “PixelSmash” flaw enables remote code execution.

23.06.2026

FFmpeg “PixelSmash” flaw enables remote code execution. Security researchers disclosed a vulnerability in FFmpeg’s libavcodec library, tracked as CVE-2026-8461. The flaw affects media-processing software and can be triggered with crafted video files.

Източник: www.securityweek.com

FFmpeg “PixelSmash” flaw enables remote code execution.

Security researchers disclosed a vulnerability in FFmpeg’s libavcodec library, tracked as CVE-2026-8461. The flaw affects media-processing software and can be triggered with crafted video files. SecurityWeek reported that it can affect desktop players, media servers, NAS appliances, cloud transcoding systems, and thumbnail generators. FFmpeg version 8.1.2 contains the fix