FFmpeg patches “PixelSmash” in MagicYUV: what users of media apps should know

Originally published at: FFmpeg patches “PixelSmash” in MagicYUV: what users of media apps should know - ToolsLib Blog

FFmpeg fixed “PixelSmash” (CVE-2026-8461) in the MagicYUV decoder, a flaw that can crash applications and, under specific conditions, enable RCE. A separate RASC decoder bug (CVE-2026-12706) can also cause crashes when parsing malicious AVI files.