FeedVulnerabilityFFmpeg fixes PixelSmash flaw in widely used video decoder...
VulnerabilityBleeping Computer
7.5HIGH

FFmpeg fixes PixelSmash flaw in widely used video decoder

📅 22 June 2026 at 21:05 UTC📰 Bleeping ComputerView original source ↗
FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service  condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A newly disclosed FFmpeg flaw, PixelSmash, can be exploited for remote code execution on Jellyfin servers and trigger denial-of-service conditions in various applications, including Kodi, Emby, and OBS Studio.

⚙️Technical Details
Affected Systems
JellyfinKodiEmbyOBS Studio
Attack Vectors
malicious video file in AVI, MKV, or MOV formatthumbnail generationautomated media ingestion workflow
💥Impact Assessment
Severity: high
Who Is at Risk
users of affected applicationsJellyfin serversSeverity: high
🛡️Recommended Actions
1Apply patches or updates to FFmpeg version 8.1.2
2Disable ASLR defense on vulnerable systems
3Implement additional security measures, such as file format blocklists
📦Affected Products
FFmpegJellyfin

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed