iris_release_internal_buffers of the component media. The manipulation results in use after free.This vulnerability was named CVE-2026-46240. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.