CVE-2026-107676: FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer
FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in avdynamichdrplustot35() that leaves up to three payload bytes uninitialized when tonemappingflag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker needs to supply crafted HDR10+ metadata through Matroska T.35 BlockAdditional data or HEVC/AV1 SEI metadata. The vulnerable metadata must be processed during remuxing or transcoding so FFmpeg writes the serialized data to an output file.
What data can be exposed?
When tone_mapping_flag is 0, av_dynamic_hdr_plus_to_t35() can leave up to three payload bytes uninitialized. Those bytes may contain process memory and can be written into the generated output file.
How can I assess whether an output may be affected?
Review workflows that remux or transcode untrusted Matroska, HEVC, or AV1 inputs containing HDR10+ metadata. Outputs generated from crafted metadata with tone_mapping_flag set to 0 may contain the leaked bytes.