Description
FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.
Published: 2026-10-08
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

FFmpeg versions through 9.0.2 contain a vulnerability in the function av_dynamic_hdr_plus_to_t35() that fails to initialize all bytes of a payload buffer when the tone_mapping_flag is set to 0. As a result, the function may expose up to three bytes of arbitrary process memory. An attacker can exploit this by inserting carefully crafted Matroska T.35 BlockAdditional data or HEVC/AV1 SEI metadata into a media file. When the file is subsequently remixed or transcoded, the uninitialized bytes are written into the output file, leaking sensitive memory content. The weakness is classified as CWE-908: Uninitialized Memory Reference.

Affected Systems

All versions of FFmpeg up to and including 9.0.2 are affected, including the distribution used in many multimedia pipelines, container libraries, and streaming servers. The vulnerability is tied to FFmpeg's HDR10+ metadata serialization path, which is invoked when processing HDR10+ compliant media streams. The fix was introduced in the commit referenced in the advisory, but older releases lack the patch.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact, and because the vulnerability requires a crafted media file to be processed, it is likely exploitable by users who can provide input to an FFmpeg instance. The EPSS score is not publicly available, and the vulnerability is not listed in CISA's KEV catalog. An attacker with the ability to supply or influence media files for remuxing or transcoding can cause accidental exposure of memory contents in generated output files, potentially revealing sensitive data that resides in the process address space. The risk is increased in environments where FFmpeg is exposed to untrusted input or where it runs with elevated privileges.

Generated by OpenCVE AI on October 8, 2026 at 17:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest FFmpeg release that includes the fix for HDR10+ metadata serialization.
  • Validate or sanitize input media files before remuxing or transcoding to prevent untrusted metadata from being processed.
  • Enforce least privilege for processes handling media conversion to limit the potential impact of memory disclosure.

Generated by OpenCVE AI on October 8, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.
Title FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-908
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T15:28:41.795Z

Reserved: 2026-10-08T15:11:27.937Z

Link: CVE-2026-107676

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:05.247

Modified: 2026-10-08T16:17:05.247

Link: CVE-2026-107676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:00:18Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource