Commit 2c2f6e96e3 for ffmpeg

commit 2c2f6e96e31795ae95a8f8323a493ffbc493111f
Author: Joshua Rogers <MegaManSec@users.noreply.github.com>
Date:   Mon Aug 31 15:31:18 2026 +0200

    avutil/hdr_dynamic_metadata: fix uninitialized bytes when color saturation is set without tone mapping

    The write loop in av_dynamic_hdr_plus_to_t35() nested the
    color_saturation_mapping_flag and color_saturation_weight put_bits
    calls inside the tone_mapping_flag block, while the size calculation
    and the parser treat these fields as unconditional per window. When
    tone_mapping_flag is 0 and color_saturation_mapping_flag is 1, fewer
    bits than allocated were written, leaving uninitialized heap bytes in
    the returned buffer. Move the writes outside the tone_mapping_flag
    block to match.

    Fixes: read of uninitialized memory
    Fixes: Yy1uJcbmyeBp
    Fixes: AISLE-2026-0100-00011
    Found-by: Joshua Rogers <joshua.rogers@aisle.com>

diff --git a/libavutil/hdr_dynamic_metadata.c b/libavutil/hdr_dynamic_metadata.c
index 4c9ac25970..9b46499343 100644
--- a/libavutil/hdr_dynamic_metadata.c
+++ b/libavutil/hdr_dynamic_metadata.c
@@ -379,11 +379,11 @@ int av_dynamic_hdr_plus_to_t35(const AVDynamicHDRPlus *s, uint8_t **data, size_t
             for (int i = 0; i < s->params[w].num_bezier_curve_anchors; i++)
                 put_bits(pb, 10, s->params[w].bezier_curve_anchors[i].num * bezier_anchor_den /
                     s->params[w].bezier_curve_anchors[i].den);
-            put_bits(pb, 1, s->params[w].color_saturation_mapping_flag);
-            if (s->params[w].color_saturation_mapping_flag)
-                put_bits(pb, 6, s->params[w].color_saturation_weight.num * saturation_weight_den /
-                    s->params[w].color_saturation_weight.den);
         }
+        put_bits(pb, 1, s->params[w].color_saturation_mapping_flag);
+        if (s->params[w].color_saturation_mapping_flag)
+            put_bits(pb, 6, s->params[w].color_saturation_weight.num * saturation_weight_den /
+                s->params[w].color_saturation_weight.den);
     }

     flush_put_bits(pb);