Skip to content

Security fix: patched FFmpeg (PixelSmash / CVE-2026-8461)

Latest

Choose a tag to compare

@stevezau stevezau released this 22 Jul 23:04
6fbd763

Fixes

  • Security: Updated the bundled FFmpeg to 8.1.2, closing CVE-2026-8461 ("PixelSmash") — a high-severity flaw in FFmpeg's MagicYUV video decoder that a maliciously crafted media file could exploit during preview generation. Both the primary (jellyfin-ffmpeg) and fallback FFmpeg binaries in the image are now patched. Dolby Vision Profile 5 handling on Intel GPUs is unaffected — the updated build keeps the DV tone-mapping patch. Rebuild/repull the image to get the fix.