Uninitialized Memory Disclosure in FFmpeg Product by FFmpeg
CVE-2026-107676
4.8MEDIUM
What is CVE-2026-107676?
The vulnerability in FFmpeg versions up to 9.0.2 stems from uninitialized memory disclosure within the av_dynamic_hdr_plus_to_t35() function. When the tone_mapping_flag is set to 0, three payload bytes may remain uninitialized, allowing attackers to exploit this flaw. By supplying specially crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata, an attacker could execute remuxing or transcoding that inadvertently writes sensitive leaked process memory into the output files, posing a significant risk of data exposure.
Affected Version(s)
FFmpeg 0 <= 9.0.2
