Uninitialized Memory Disclosure in FFmpeg Product by FFmpeg
CVE-2026-107676

4.8MEDIUM

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107676?

The vulnerability in FFmpeg versions up to 9.0.2 stems from uninitialized memory disclosure within the av_dynamic_hdr_plus_to_t35() function. When the tone_mapping_flag is set to 0, three payload bytes may remain uninitialized, allowing attackers to exploit this flaw. By supplying specially crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata, an attacker could execute remuxing or transcoding that inadvertently writes sensitive leaked process memory into the output files, posing a significant risk of data exposure.

Affected Version(s)

FFmpeg 0 <= 9.0.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers (AISLE Research)
.