PT-2026-108037 · FFmpeg · Ffmpeg

·

CVE-2026-107676

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av dynamic hdr plus to t35() that leaves up to three payload bytes uninitialized when tone mapping flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107676

Affected Products

Ffmpeg