Impact
FFmpeg versions through 9.0.2 contain a vulnerability in the function av_dynamic_hdr_plus_to_t35() that fails to initialize all bytes of a payload buffer when the tone_mapping_flag is set to 0. As a result, the function may expose up to three bytes of arbitrary process memory. An attacker can exploit this by inserting carefully crafted Matroska T.35 BlockAdditional data or HEVC/AV1 SEI metadata into a media file. When the file is subsequently remixed or transcoded, the uninitialized bytes are written into the output file, leaking sensitive memory content. The weakness is classified as CWE-908: Uninitialized Memory Reference.
Affected Systems
All versions of FFmpeg up to and including 9.0.2 are affected, including the distribution used in many multimedia pipelines, container libraries, and streaming servers. The vulnerability is tied to FFmpeg's HDR10+ metadata serialization path, which is invoked when processing HDR10+ compliant media streams. The fix was introduced in the commit referenced in the advisory, but older releases lack the patch.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, and because the vulnerability requires a crafted media file to be processed, it is likely exploitable by users who can provide input to an FFmpeg instance. The EPSS score is not publicly available, and the vulnerability is not listed in CISA's KEV catalog. An attacker with the ability to supply or influence media files for remuxing or transcoding can cause accidental exposure of memory contents in generated output files, potentially revealing sensitive data that resides in the process address space. The risk is increased in environments where FFmpeg is exposed to untrusted input or where it runs with elevated privileges.
OpenCVE Enrichment