{"id":"CVE-2026-107676","title":"FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0","summary":"FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 Bl…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":["CWE-908"],"vendor":"FFmpeg","product":"FFmpeg","affected":["FFmpeg <= 9.0.2"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:04:38.633","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107676","references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2c2f6e96e31795ae95a8f8323a493ffbc493111f","label":"disclosure@vulncheck.com"},{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24590","label":"disclosure@vulncheck.com"},{"url":"https://ffmpeg.org/","label":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/hdr_dynamic_metadata.c#L374-L385","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-uninitialized-memory-disclosure-via-hdr10-metadata-serializer","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T15:49:37.998Z","slug":"CVE-2026-107676","body":"## Overview\n\nFFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}