Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package ffmpeg-7 for openSUSE:Factory checked in at 2026-09-02 17:00:31 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/ffmpeg-7 (Old) and /work/SRC/openSUSE:Factory/.ffmpeg-7.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "ffmpeg-7" Wed Sep 2 17:00:31 2026 rev:31 rq:1375210 version:7.1.5 Changes: -------- --- /work/SRC/openSUSE:Factory/ffmpeg-7/ffmpeg-7.changes 2026-07-26 16:37:26.664957826 +0200 +++ /work/SRC/openSUSE:Factory/.ffmpeg-7.new.1265/ffmpeg-7.changes 2026-09-02 17:00:35.052844676 +0200 @@ -1,0 +2,196 @@ +Mon Aug 28 05:22:38 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75147.patch: + Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU + size in the keyframe search loop. + (CVE-2026-75147, bsc#1276413) + +------------------------------------------------------------------- +Mon Aug 28 04:47:54 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75146.patch: + Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative + fragment index. + (CVE-2026-75146, bsc#1276412) + +------------------------------------------------------------------- +Mon Aug 28 04:02:17 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75145.patch: + Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow + the OBU size to (long). + (CVE-2026-75145, bsc#1276411) + +------------------------------------------------------------------- +Mon Aug 28 03:34:50 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75144.patch: + Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data + units larger than the RTP payload buffer. + (CVE-2026-75144, bsc#1276410) + +------------------------------------------------------------------- +Mon Aug 28 03:17:21 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75143.patch: + Backport 1c10bcc2 from upstream, avformat/librist: honor the caller + buffer size in librist_read. + (CVE-2026-75143, bsc#1276409) + +------------------------------------------------------------------- +Mon Aug 28 02:58:12 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75142.patch: + Backport 9d786e4b from upstream, avformat/mpegenc: reject stream + counts that overflow the system header. + (CVE-2026-75142, bsc#1276408) + +------------------------------------------------------------------- +Mon Aug 28 02:44:56 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-75141.patch: + Backport acf5d7cd from upstream, avformat/hevc: reject hvcC + NAL arrays that overflow the 16-bit count. + (CVE-2026-75141, bsc#1276407) + +------------------------------------------------------------------- +Wed Aug 14 09:44:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-70632.patch: + Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 + output wider than the plane. + (CVE-2026-70632, bsc#1274289) + +------------------------------------------------------------------- +Wed Aug 14 08:27:41 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-70631.patch: + Backport 3c287af3 from upstream, avcodec/tiff: reject inflate + output shorter than the strip. + (CVE-2026-70631, bsc#1274287) + +------------------------------------------------------------------- +Wed Aug 14 07:58:24 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-70630.patch: + Backport c22667d0 from upstream, avcodec/screenpresso: reject + deflate output shorter than the frame. + (CVE-2026-70630, bsc#1274282) + +------------------------------------------------------------------- +Wed Aug 14 07:22:18 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-70629.patch: + Backport a5fe21a1 from upstream, avcodec/rscc: do not leave + uninitilized data when the input is too short. + (CVE-2026-70629, bsc#1274270) + +------------------------------------------------------------------- +Wed Aug 14 06:52:11 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-70628.patch: + Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid + signed overflow in the capacity check. + (CVE-2026-70628, bsc#1274268) + +------------------------------------------------------------------- +Wed Aug 14 06:41:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-66037.patch: + Backport f15e730c from upstream, avformat/iamf_parse: check + count_label against the available bytes. + (CVE-2026-66037, bsc#1272764) + +------------------------------------------------------------------- +Wed Aug 14 06:28:33 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-66036.patch: + Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support + dynamic frame sizes. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 06:09:17 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-66036-shim02.patch + Backport 4f623b4c from upstream, avfilter/vf_libplacebo: implement + rotation option. This patch is for facilitate ffmpeg-CVE-2026-66036.patch. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 05:51:42 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-66036-shim01.patch + Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject + unsupported frame parameter changes. This patch is for facilitate + ffmpeg-CVE-2026-66036.patch. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 05:31:22 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-65706.patch: + Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the + temp row buffer for the widest plane. + (CVE-2026-65706, bsc#1272762) + +------------------------------------------------------------------- +Wed Aug 14 04:56:09 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-65705.patch: + Backport 30a52276 from upstream, avfilter/vf_floodfill: remove + unneeded variables. + (CVE-2026-65705, bsc#1272761) + +------------------------------------------------------------------- +Wed Aug 14 04:31:19 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-65704.patch: + Backport 52f7983f from upstream, avformat/ty: don't let the Series2 + AC3 trim underflow the packet size. + (CVE-2026-65704, bsc#1272760) + +------------------------------------------------------------------- +Wed Aug 14 04:02:11 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-65703.patch: + Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference + frame before reallocating on size change. + (CVE-2026-65703, bsc#1272759) + +------------------------------------------------------------------- +Wed Aug 14 03:46:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-64834.patch: + Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF + objects smaller than their header. + (CVE-2026-64834, bsc#1272757) + +------------------------------------------------------------------- +Wed Aug 14 03:33:14 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-64833.patch: + Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS + core_size against the packet size in the HD path. + (CVE-2026-64833, bsc#1272755) + +------------------------------------------------------------------- +Wed Aug 14 03:28:13 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-7-CVE-2026-58049.patch: + Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit + DLTA accesses stay within the row. + (CVE-2026-58049, bsc#1269550) + +------------------------------------------------------------------- +Thu Jul 30 02:39:03 UTC 2026 - Xiaoguang Wang <[email protected]> + +- Add CVE patches: + ffmpeg-7-CVE-2026-64835.patch: (CVE-2026-64835, bsc#1272758) + ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754) + ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752) + ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768) + ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765) + ffmpeg-7-CVE-2026-66041.patch: (CVE-2026-66041, bsc#1272767) + +------------------------------------------------------------------- @@ -12,0 +209,4 @@ + * avcodec/magicyuv: reject slice_height misaligned with chroma vshift. + (CVE-2026-8461, bsc#1269490) + * avcodec/magicyuv: Expand the s->interlaced slice-height sanity check. + (CVE-2026-8461, bsc#1269490) @@ -122,0 +323,2 @@ + * avformat/hls: Be more picky on extensions. + (CVE-2023-6602, bsc#1220546, CVE-2023-6604, bsc#1220549) @@ -216,0 +419,4 @@ + * avcodec/vp9: Fix race when attaching side-data for show-existing frame. (commit: 0ba0585) + (CVE-2024-36615, bsc#1234017) + * lavc/vp9: Fix regression introduced in 0ba0585. + (CVE-2024-36615, bsc#1234017) @@ -284,0 +491,3 @@ + * avcodec/ppc/vp8dsp_altivec: Fix out-of-bounds access h_subpel_filters_inner[i] and + h_subpel_filters_outer[i / 2] belong together and the former allows the range 0..6. + (CVE-2024-35367, bsc#1234029) New: ---- ffmpeg-7-CVE-2026-58049.patch ffmpeg-7-CVE-2026-64830.patch ffmpeg-7-CVE-2026-64832.patch ffmpeg-7-CVE-2026-64833.patch ffmpeg-7-CVE-2026-64834.patch ffmpeg-7-CVE-2026-64835.patch ffmpeg-7-CVE-2026-65703.patch ffmpeg-7-CVE-2026-65704.patch ffmpeg-7-CVE-2026-65705.patch ffmpeg-7-CVE-2026-65706.patch ffmpeg-7-CVE-2026-66036-shim01.patch ffmpeg-7-CVE-2026-66036-shim02.patch ffmpeg-7-CVE-2026-66036.patch ffmpeg-7-CVE-2026-66037.patch ffmpeg-7-CVE-2026-66038.patch ffmpeg-7-CVE-2026-66039.patch ffmpeg-7-CVE-2026-66041.patch ffmpeg-7-CVE-2026-70628.patch ffmpeg-7-CVE-2026-70629.patch ffmpeg-7-CVE-2026-70630.patch ffmpeg-7-CVE-2026-70631.patch ffmpeg-7-CVE-2026-70632.patch ffmpeg-7-CVE-2026-75141.patch ffmpeg-7-CVE-2026-75142.patch ffmpeg-7-CVE-2026-75143.patch ffmpeg-7-CVE-2026-75144.patch ffmpeg-7-CVE-2026-75146.patch ----------(New B)---------- New: - Add ffmpeg-7-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit New: ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754) ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752) ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768) New: ffmpeg-7-CVE-2026-64835.patch: (CVE-2026-64835, bsc#1272758) ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754) ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752) New: - Add ffmpeg-7-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS New: - Add ffmpeg-7-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF New:- Add CVE patches: ffmpeg-7-CVE-2026-64835.patch: (CVE-2026-64835, bsc#1272758) ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754) New: - Add ffmpeg-7-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference New: - Add ffmpeg-7-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 New: - Add ffmpeg-7-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove New: - Add ffmpeg-7-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the New: - Add ffmpeg-7-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject New: - Add ffmpeg-7-CVE-2026-66036-shim02.patch Backport 4f623b4c from upstream, avfilter/vf_libplacebo: implement New: - Add ffmpeg-7-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support New: - Add ffmpeg-7-CVE-2026-66037.patch: Backport f15e730c from upstream, avformat/iamf_parse: check New: ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752) ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768) ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765) New: ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768) ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765) ffmpeg-7-CVE-2026-66041.patch: (CVE-2026-66041, bsc#1272767) New: ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765) ffmpeg-7-CVE-2026-66041.patch: (CVE-2026-66041, bsc#1272767) New: - Add ffmpeg-7-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid New: - Add ffmpeg-7-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave New: - Add ffmpeg-7-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject New: - Add ffmpeg-7-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate New: - Add ffmpeg-7-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 New: - Add ffmpeg-7-CVE-2026-75141.patch: Backport acf5d7cd from upstream, avformat/hevc: reject hvcC New: - Add ffmpeg-7-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream New: - Add ffmpeg-7-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller New: - Add ffmpeg-7-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data New: - Add ffmpeg-7-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ ffmpeg-7.spec ++++++ --- /var/tmp/diff_new_pack.pkjLuE/_old 2026-09-02 17:00:36.362889679 +0200 +++ /var/tmp/diff_new_pack.pkjLuE/_new 2026-09-02 17:00:36.364889747 +0200 @@ -120,6 +120,34 @@ Patch5: work-around-abi-break.patch Patch6: ffmpeg-chromium.patch Patch7: 11013-avcodec-decode-clean-up-if-get_hw_frames_parameters-.patch +Patch8: ffmpeg-7-CVE-2026-64835.patch +Patch9: ffmpeg-7-CVE-2026-64832.patch +Patch10: ffmpeg-7-CVE-2026-64830.patch +Patch11: ffmpeg-7-CVE-2026-66038.patch +Patch12: ffmpeg-7-CVE-2026-66039.patch +Patch13: ffmpeg-7-CVE-2026-66041.patch +Patch14: ffmpeg-7-CVE-2026-58049.patch +Patch15: ffmpeg-7-CVE-2026-64833.patch +Patch16: ffmpeg-7-CVE-2026-64834.patch +Patch17: ffmpeg-7-CVE-2026-65703.patch +Patch18: ffmpeg-7-CVE-2026-65704.patch +Patch19: ffmpeg-7-CVE-2026-65705.patch +Patch20: ffmpeg-7-CVE-2026-65706.patch +Patch21: ffmpeg-7-CVE-2026-66036-shim01.patch +Patch22: ffmpeg-7-CVE-2026-66036-shim02.patch +Patch23: ffmpeg-7-CVE-2026-66036.patch +Patch24: ffmpeg-7-CVE-2026-66037.patch +Patch25: ffmpeg-7-CVE-2026-70628.patch +Patch26: ffmpeg-7-CVE-2026-70629.patch +Patch27: ffmpeg-7-CVE-2026-70630.patch +Patch28: ffmpeg-7-CVE-2026-70631.patch +Patch29: ffmpeg-7-CVE-2026-70632.patch +Patch30: ffmpeg-7-CVE-2026-75141.patch +Patch31: ffmpeg-7-CVE-2026-75142.patch +Patch32: ffmpeg-7-CVE-2026-75143.patch +Patch33: ffmpeg-7-CVE-2026-75144.patch +Patch34: ffmpeg-7-CVE-2026-75146.patch +# There is another Patch section further below! BuildRequires: ladspa-devel BuildRequires: libgsm-devel BuildRequires: nasm @@ -827,11 +855,18 @@ Source3: ffmpeg-7-rpmlintrc Source98: http://ffmpeg.org/ffmpeg-devel.asc#/ffmpeg-7.keyring Patch1: ffmpeg-arm6l.diff +Patch2: ffmpeg-new-coder-errors.diff Patch3: ffmpeg-codec-choice.diff Patch4: ffmpeg-4.2-dlopen-fdk_aac.patch Patch5: work-around-abi-break.patch Patch6: ffmpeg-chromium.patch Patch7: 11013-avcodec-decode-clean-up-if-get_hw_frames_parameters-.patch +Patch8: ffmpeg-7-CVE-2026-64835.patch +Patch9: ffmpeg-7-CVE-2026-64832.patch +Patch10: ffmpeg-7-CVE-2026-64830.patch +Patch11: ffmpeg-7-CVE-2026-66038.patch +Patch12: ffmpeg-7-CVE-2026-66039.patch +Patch13: ffmpeg-7-CVE-2026-66041.patch BuildRequires: c_compiler BuildRequires: pkgconfig(openh264) Requires: this-is-only-for-build-envs ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.pkjLuE/_old 2026-09-02 17:00:36.430892015 +0200 +++ /var/tmp/diff_new_pack.pkjLuE/_new 2026-09-02 17:00:36.433892118 +0200 @@ -1,5 +1,5 @@ -mtime: 1785070704 -commit: 4cffdaa568cc153bcc70385d4936802ac42a7ffc31db253b07f262d4242c72f6 -url: https://src.opensuse.org/jengelh/ffmpeg-7 -revision: master +mtime: 1788290258 +commit: e96d75e8799e64715c1101a406dbc2157bed4b150731c6d6d8313c6e106fcf57 +url: https://src.opensuse.org/jengelh/ffmpeg +revision: ff7 ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-01 21:17:38.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ ffmpeg-7-CVE-2026-58049.patch ++++++ >From f8d7795dcca36a4dd412e89cbd83e3dfec1e0d81 Mon Sep 17 00:00:00 2001 From: Umar Pathan <[email protected]> Date: Sun, 28 Jun 2026 23:02:52 +0200 Subject: [PATCH] avcodec/rasc: Check that 32-bit DLTA accesses stay within the row Found-by: bikini (github.com/bikini/exploitarium) Fixes: out of array access Fixes: rowspill_128x1.avi / gen_rowspill_avi.py Fixes: xGV79bIb7uAJ (cherry picked from commit 11ff18a6c80187405fc492f9bb07ba9f2f663f76) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rasc.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/libavcodec/rasc.c b/libavcodec/rasc.c index 5f956a9b2c..d784a44063 100644 --- a/libavcodec/rasc.c +++ b/libavcodec/rasc.c @@ -320,6 +320,11 @@ static int decode_move(AVCodecContext *avctx, return 0; } +static inline int dlta_room(unsigned cx, unsigned w, unsigned bpp, unsigned need) +{ + return cx + need <= w * bpp; +} + #define NEXT_LINE \ if (cx >= w * s->bpp) { \ cx = 0; \ @@ -418,6 +423,8 @@ static int decode_dlta(AVCodecContext *avctx, case 4: fill = bytestream2_get_byte(&dc); while (len > 0 && cy > 0) { + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx++; @@ -427,6 +434,8 @@ static int decode_dlta(AVCodecContext *avctx, case 7: fill = bytestream2_get_le32(&dc); while (len > 0 && cy > 0) { + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx += 4; @@ -443,6 +452,8 @@ static int decode_dlta(AVCodecContext *avctx, while (len > 0 && cy > 0) { unsigned v0, v1; + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; v0 = AV_RL32(b2 + cx); v1 = AV_RL32(b1 + cx); AV_WL32(b2 + cx, v1); @@ -454,6 +465,8 @@ static int decode_dlta(AVCodecContext *avctx, case 13: while (len > 0 && cy > 0) { fill = bytestream2_get_le32(&dc); + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx += 4; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-64830.patch ++++++ >From dbd495f066a85ba96b17433f4306582aa37c3951 Mon Sep 17 00:00:00 2001 From: Pavel Kohout <[email protected]> Date: Mon, 29 Jun 2026 23:30:41 +0200 Subject: [PATCH] avformat/vobsub: reuse subtitle streams and bound the stream count Fixes: heap buffer overflow Fixes: lqaO5R1BaZGO Fixes: dbfe61100b (avformat/vobsub: fix several issues.) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/mpeg.c | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/libavformat/mpeg.c b/libavformat/mpeg.c index ff5ced8107..29abe329b9 100644 --- a/libavformat/mpeg.c +++ b/libavformat/mpeg.c @@ -841,6 +841,20 @@ static int vobsub_read_header(AVFormatContext *s) } if (!st || st->id != stream_id) { + st = NULL; + for (i = 0; i < s->nb_streams; i++) { + if (s->streams[i]->id == stream_id) { + st = s->streams[i]; + break; + } + } + } + if (!st) { + if (s->nb_streams >= FF_ARRAY_ELEMS(vobsub->q)) { + av_log(s, AV_LOG_ERROR, "Maximum number of subtitle streams reached\n"); + ret = AVERROR_INVALIDDATA; + goto end; + } st = avformat_new_stream(s, NULL); if (!st) { ret = AVERROR(ENOMEM); @@ -865,14 +879,14 @@ static int vobsub_read_header(AVFormatContext *s) timestamp = (hh*3600LL + mm*60LL + ss) * 1000LL + ms + delay; timestamp = av_rescale_q(timestamp, av_make_q(1, 1000), st->time_base); - sub = ff_subtitles_queue_insert(&vobsub->q[s->nb_streams - 1], "", 0, 0); + sub = ff_subtitles_queue_insert(&vobsub->q[st->index], "", 0, 0); if (!sub) { ret = AVERROR(ENOMEM); goto end; } sub->pos = pos; sub->pts = timestamp; - sub->stream_index = s->nb_streams - 1; + sub->stream_index = st->index; } else if (!strncmp(line, "alt:", 4)) { const char *p = line + 4; -- 2.54.0 ++++++ ffmpeg-7-CVE-2026-64832.patch ++++++ >From 4c6217477fc64305055b37d9d1d0d76d30e37f97 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Tue, 30 Jun 2026 00:24:07 +0200 Subject: [PATCH] avcodec/nvdec: don't double free the fdd-owned context on the sep_ref error path Fixes: double free Fixes: rpSz7v3yq2u8 Fixes: 72982f8cb5dad6252a14226d28128313eed4a5ff (avcodec/nvdec: add support for separate reference frame) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/nvdec.c | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) Index: ffmpeg-7.1.5/libavcodec/nvdec.c =================================================================== --- ffmpeg-7.1.5.orig/libavcodec/nvdec.c +++ ffmpeg-7.1.5/libavcodec/nvdec.c @@ -614,8 +614,7 @@ int ff_nvdec_start_frame_sep_ref(AVCodec cf->ref_idx_ref = ff_refstruct_pool_get(ctx->decoder_pool); if (!cf->ref_idx_ref) { av_log(avctx, AV_LOG_ERROR, "No decoder surfaces left\n"); - ret = AVERROR(ENOMEM); - goto fail; + return AVERROR(ENOMEM); } } cf->ref_idx = *cf->ref_idx_ref; @@ -625,9 +624,6 @@ int ff_nvdec_start_frame_sep_ref(AVCodec } return 0; -fail: - nvdec_fdd_priv_free(cf); - return ret; } int ff_nvdec_end_frame(AVCodecContext *avctx) ++++++ ffmpeg-7-CVE-2026-64833.patch ++++++ >From 385ac2fadcb4394ec4f65e5c4d3d24003e090f36 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Tue, 30 Jun 2026 00:11:50 +0200 Subject: [PATCH] avformat/spdifenc: bound DTS core_size against the packet size in the HD path Fixes: out of array read Fixes: yBSax492UIB9 Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 6f80e2765492700622596af720534cef33dd31b4) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/spdifenc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c index ab3f73da0d..16eebda01c 100644 --- a/libavformat/spdifenc.c +++ b/libavformat/spdifenc.c @@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size, * (dtshd_fallback == 0) */ ctx->dtshd_skip = 1; } - if (ctx->dtshd_skip && core_size) { + if (ctx->dtshd_skip && core_size && core_size <= pkt->size) { pkt_size = core_size; if (ctx->dtshd_fallback >= 0) --ctx->dtshd_skip; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-64834.patch ++++++ >From 3c441711a343ccf50196c70a3f0b554b52f8d9de Mon Sep 17 00:00:00 2001 From: Pavel Kohout <[email protected]> Date: Tue, 30 Jun 2026 21:55:16 +0200 Subject: [PATCH] avformat/rtpdec_asf: reject ASF objects smaller than their header Fixes: infinite loop Fixes: MzWwJdpZF2Ls Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet parsing.) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 11d5f475be95d22d5f0692220cc772b116abc632) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/rtpdec_asf.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c index b3b346f3cc..f7fa69e27f 100644 --- a/libavformat/rtpdec_asf.c +++ b/libavformat/rtpdec_asf.c @@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len) uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid)); int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2; if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) { + if (chunksize < sizeof(ff_asf_guid) + 8) + return -1; if (chunksize > end - p) return -1; p += chunksize; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-64835.patch ++++++ >From 1836ef96846937a6cc2443698a693104f5c0b21e Mon Sep 17 00:00:00 2001 From: Pavel Kohout <[email protected]> Date: Mon, 29 Jun 2026 23:46:16 +0200 Subject: [PATCH] avcodec/adx: sync decoder channel state on NEW_EXTRADATA Fixes: out of array access Fixes: heaNtmHvklpe Fixes: 92396cee602320c714713ca2d93b53684ad57000 (avformat: add CRI AAX demuxer) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/adxdec.c | 5 +++++ 1 file changed, 5 insertions(+) Index: ffmpeg-7.1.5/libavcodec/adxdec.c =================================================================== --- ffmpeg-7.1.5.orig/libavcodec/adxdec.c +++ ffmpeg-7.1.5/libavcodec/adxdec.c @@ -172,6 +172,7 @@ static int adx_decode_frame(AVCodecConte new_extradata = av_packet_get_side_data(avpkt, AV_PKT_DATA_NEW_EXTRADATA, &new_extradata_size); if (new_extradata && new_extradata_size > 0) { + int old_channels = c->channels; int header_size; if ((ret = adx_decode_header(avctx, new_extradata, new_extradata_size, &header_size, @@ -180,6 +181,10 @@ static int adx_decode_frame(AVCodecConte return AVERROR_INVALIDDATA; } + c->channels = avctx->ch_layout.nb_channels; + c->header_parsed = 1; + if (old_channels != c->channels) + memset(c->prev, 0, sizeof(c->prev)); c->eof = 0; } ++++++ ffmpeg-7-CVE-2026-65703.patch ++++++ >From 3b85fbe89025ea696988488358dfde41a09c53c5 Mon Sep 17 00:00:00 2001 From: Cloud-LHY <[email protected]> Date: Fri, 10 Jul 2026 04:07:04 +0200 Subject: [PATCH] avcodec/tdsc: unref the reference frame before reallocating on size change Fixes: out of array access Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py Fixes: p9xG4xGf9P7H Fixes: HQL7a1WgTdHZ Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS Found-by: Adrian Junge (vurlo) (cherry picked from commit fd3ee52fab34d98a95b787d0b5ff45685766200c) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/tdsc.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c index ca9dd0f0a6..102b4ae966 100644 --- a/libavcodec/tdsc.c +++ b/libavcodec/tdsc.c @@ -485,11 +485,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int number_tiles) return ret; init_refframe = 1; } - ctx->refframe->width = ctx->width = w; - ctx->refframe->height = ctx->height = h; + ctx->width = w; + ctx->height = h; /* Allocate the reference frame if not already done or on size change */ if (init_refframe) { + av_frame_unref(ctx->refframe); + ctx->refframe->format = avctx->pix_fmt; + ctx->refframe->width = w; + ctx->refframe->height = h; ret = av_frame_get_buffer(ctx->refframe, 0); if (ret < 0) return ret; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-65704.patch ++++++ >From 52f7983f15678c8a6065327760d7b6eb1c9c84ed Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Fri, 10 Jul 2026 04:07:35 +0200 Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the packet size Fixes: negative-size-param Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py Fixes: g0qeE6KvrjZi Found-by: Adrian Junge (vurlo) (cherry picked from commit de771bd52774a52d45b0e2c82e56995a1ef40df7) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/ty.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/ty.c b/libavformat/ty.c index 9be027fcca..842d97038c 100644 --- a/libavformat/ty.c +++ b/libavformat/ty.c @@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt) if (ty->audio_type == TIVO_AUDIO_AC3 && ty->tivo_series == TIVO_SERIES2) { if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) { - pkt->size -= 2; + pkt->size -= FFMIN(pkt->size, 2); ty->ac3_pkt_size = 0; } else { ty->ac3_pkt_size += pkt->size; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-65705.patch ++++++ >From 30a52276f9dff60fe732d8bb8d463e587ff69c94 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 03:27:47 +0200 Subject: [PATCH] avfilter/vf_floodfill: remove unneeded variables Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit f186c50cf53aec20e9a29059cb22ca3f2d59201c) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_floodfill.c | 35 ++++++++++++++++------------------- 1 file changed, 16 insertions(+), 19 deletions(-) diff a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c --- a/libavfilter/vf_floodfill.c +++ b/libavfilter/vf_floodfill.c @@ -39,7 +39,6 @@ int d[4]; int nb_planes; - int back, front; Points *points; int (*is_same)(const AVFrame *frame, int x, int y, @@ -270,7 +269,6 @@ } } - s->front = s->back = 0; s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points)); if (!s->points) return AVERROR(ENOMEM); @@ -293,6 +291,7 @@ const int w = frame->width; const int h = frame->height; int i, ret; + int front = 0; if (is_inside(s->x, s->y, w, h)) { s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); @@ -310,9 +309,9 @@ goto end; if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) { - s->points[s->front].x = s->x; - s->points[s->front].y = s->y; - s->front++; + s->points[front].x = s->x; + s->points[front].y = s->y; + front++; } if (ret = ff_inlink_make_frame_writable(link, &frame)) { @@ -320,34 +319,34 @@ return ret; } - while (s->front > s->back) { + while (front > 0) { int x, y; - s->front--; - x = s->points[s->front].x; - y = s->points[s->front].y; + front--; + x = s->points[front].x; + y = s->points[front].y; if (s->is_same(frame, x, y, s0, s1, s2, s3)) { s->set_pixel(frame, x, y, d0, d1, d2, d3); if (is_inside(x + 1, y, w, h)) { - s->points[s->front] .x = x + 1; - s->points[s->front++].y = y; + s->points[front] .x = x + 1; + s->points[front++].y = y; } if (is_inside(x - 1, y, w, h)) { - s->points[s->front] .x = x - 1; - s->points[s->front++].y = y; + s->points[front] .x = x - 1; + s->points[front++].y = y; } if (is_inside(x, y + 1, w, h)) { - s->points[s->front] .x = x; - s->points[s->front++].y = y + 1; + s->points[front] .x = x; + s->points[front++].y = y + 1; } if (is_inside(x, y - 1, w, h)) { - s->points[s->front] .x = x; - s->points[s->front++].y = y - 1; + s->points[front] .x = x; + s->points[front++].y = y - 1; } } } ++++++ ffmpeg-7-CVE-2026-65706.patch ++++++ >From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sat, 11 Jul 2026 16:46:39 +0200 Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest plane Fixes: out of array access Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py Fixes: VRAXYvKtmKa8 Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_swaprect.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c index 5d93f51c30..fe007ee5e7 100644 --- a/libavfilter/vf_swaprect.c +++ b/libavfilter/vf_swaprect.c @@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink) { AVFilterContext *ctx = inlink->dst; SwapRectContext *s = ctx->priv; + int size = 0; if (!s->w || !s->h || !s->x1 || !s->y1 || @@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink) av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc); s->nb_planes = av_pix_fmt_count_planes(inlink->format); - s->temp = av_malloc_array(inlink->w, s->pixsteps[0]); + for (int p = 0; p < s->nb_planes; p++) { + int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0; + int width = AV_CEIL_RSHIFT(inlink->w, shift); + + if (width > INT_MAX / s->pixsteps[p]) + return AVERROR(EINVAL); + size = FFMAX(size, width * s->pixsteps[p]); + } + + s->temp = av_malloc(size); if (!s->temp) return AVERROR(ENOMEM); -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-66036-shim01.patch ++++++ >From e3d0c719fddd259709c8e275942ab56af3afc35d Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 13:05:07 +0200 Subject: [PATCH] avfilter/vf_hqdn3d: reject unsupported frame parameter changes Fixes: out of array access Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py Fixes: wWDsy2oDvMuR Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++--------- libavfilter/vf_hqdn3d.h | 2 ++ 2 files changed, 27 insertions(+), 9 deletions(-) diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c index d880c2bdda..70a2ec4628 100644 --- a/libavfilter/vf_hqdn3d.c +++ b/libavfilter/vf_hqdn3d.c @@ -163,12 +163,8 @@ static int denoise_depth(HQDN3DContext *s, case 14: ret = denoise_depth(__VA_ARGS__, 14); break; \ case 16: ret = denoise_depth(__VA_ARGS__, 16); break; \ } \ - if (ret < 0) { \ - av_frame_free(&out); \ - if (!direct) \ - av_frame_free(&in); \ + if (ret < 0) \ return ret; \ - } \ } while (0) static void precalc_coefs(double dist25, int depth, int16_t *ct) @@ -281,12 +277,15 @@ static int config_input(AVFilterLink *inlink) ff_hqdn3d_init_x86(s); #endif + s->format = inlink->format; + s->width = inlink->w; + s->height = inlink->h; + return 0; } typedef struct ThreadData { AVFrame *in, *out; - int direct; } ThreadData; static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) @@ -295,7 +294,6 @@ static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) const ThreadData *td = data; AVFrame *out = td->out; AVFrame *in = td->in; - int direct = td->direct; denoise(s, in->data[job_nr], out->data[job_nr], s->line[job_nr], &s->frame_prev[job_nr], @@ -312,10 +310,21 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) { AVFilterContext *ctx = inlink->dst; AVFilterLink *outlink = ctx->outputs[0]; + HQDN3DContext *s = ctx->priv; AVFrame *out; int direct = av_frame_is_writable(in) && !ctx->is_disabled; ThreadData td; + int ret[3]; + + if (in->format != s->format || + in->width != s->width || + in->height != s->height) { + av_log(ctx, AV_LOG_ERROR, + "Frame size or format changed without filter graph reinitialization\n"); + av_frame_free(&in); + return AVERROR(EINVAL); + } if (direct) { out = in; @@ -331,9 +340,16 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) td.in = in; td.out = out; - td.direct = direct; /* one thread per plane */ - ff_filter_execute(ctx, do_denoise, &td, NULL, 3); + ff_filter_execute(ctx, do_denoise, &td, ret, 3); + for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) { + if (ret[i] < 0) { + av_frame_free(&out); + if (!direct) + av_frame_free(&in); + return ret[i]; + } + } if (ctx->is_disabled) { av_frame_free(&out); diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h index 3279bbcc77..3467f27145 100644 --- a/libavfilter/vf_hqdn3d.h +++ b/libavfilter/vf_hqdn3d.h @@ -36,6 +36,8 @@ typedef struct HQDN3DContext { double strength[4]; int hsub, vsub; int depth; + int width, height; + enum AVPixelFormat format; void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal); } HQDN3DContext; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-66036-shim02.patch ++++++ >From 4f623b4c59c3c838f588e9def7b59dcc26dee7b9 Mon Sep 17 00:00:00 2001 From: Niklas Haas <[email protected]> Date: Fri, 16 May 2025 13:05:21 +0200 Subject: [PATCH] avfilter/vf_libplacebo: implement rotation option Flipping can already be accomplished by setting the crop_w/h expressions to their negative values, so together these options can implement any of the common frame orientations. --- doc/filters.texi | 10 ++++++++++ libavfilter/avfilter.c | 3 ++- libavfilter/vf_libplacebo.c | 23 +++++++++++++++++++++++ 3 files changed, 35 insertions(+), 1 deletion(-) diff a/doc/filters.texi b/doc/filters.texi --- a/doc/filters.texi +++ b/doc/filters.texi @@ -16419,6 +16419,16 @@ and @code{(oh-ph)/2}. Set the output placement width/height expressions, default values are @code{ow} and @code{oh}. +@item rotate +Rotate the input frame clockwise by the specified angle. + +@table @samp +@item 0, 360 +@item 90 +@item 180 +@item 270 +@end table + @item fps Set the output frame rate. This can be rational, e.g. @code{60000/1001}. If set to the special string @code{none} (the default), input timestamps will diff a/libavfilter/avfilter.c b/libavfilter/avfilter.c --- a/libavfilter/avfilter.c +++ b/libavfilter/avfilter.c @@ -1032,7 +1032,8 @@ int ff_filter_frame(AVFilterLink *link, strcmp(link->dst->filter->name, "format") && strcmp(link->dst->filter->name, "idet") && strcmp(link->dst->filter->name, "null") && - strcmp(link->dst->filter->name, "scale")) { + strcmp(link->dst->filter->name, "scale") && + strcmp(link->dst->filter->name, "libplacebo")) { av_assert1(frame->format == link->format); av_assert1(frame->width == link->w); av_assert1(frame->height == link->h); diff a/libavfilter/vf_libplacebo.c b/libavfilter/vf_libplacebo.c --- a/libavfilter/vf_libplacebo.c +++ b/libavfilter/vf_libplacebo.c @@ -192,6 +192,7 @@ typedef struct LibplaceboContext { int color_range; int color_primaries; int color_trc; + int rotation; AVDictionary *extra_opts; /* pl_render_params */ @@ -787,6 +788,13 @@ static void update_crops(AVFilterContext image->crop.y0 = av_expr_eval(s->crop_y_pexpr, s->var_values, NULL); image->crop.x1 = image->crop.x0 + s->var_values[VAR_CROP_W]; image->crop.y1 = image->crop.y0 + s->var_values[VAR_CROP_H]; + image->rotation = s->rotation; + if (s->rotation % PL_ROTATION_180 == PL_ROTATION_90) { + /* Libplacebo expects the input crop relative to the actual frame + * dimensions, so un-transpose them here */ + FFSWAP(float, image->crop.x0, image->crop.y0); + FFSWAP(float, image->crop.x1, image->crop.y1); + } if (src == ref) { /* Only update the target crop once, for the 'reference' frame */ @@ -1175,6 +1183,14 @@ static int libplacebo_config_input(AVFil AVFilterContext *avctx = inlink->dst; LibplaceboContext *s = avctx->priv; + if (s->rotation % PL_ROTATION_180 == PL_ROTATION_90) { + /* Swap width and height for 90 degree rotations to make the size and + * scaling calculations work out correctly */ + FFSWAP(int, inlink->w, inlink->h); + if (inlink->sample_aspect_ratio.num) + inlink->sample_aspect_ratio = av_inv_q(inlink->sample_aspect_ratio); + } + if (inlink->format == AV_PIX_FMT_VULKAN) return ff_vk_filter_config_input(inlink); @@ -1356,6 +1372,13 @@ static const AVOption libplacebo_options {"smpte2084", NULL, 0, AV_OPT_TYPE_CONST, {.i64=AVCOL_TRC_SMPTE2084}, INT_MIN, INT_MAX, STATIC, .unit = "color_trc"}, {"arib-std-b67", NULL, 0, AV_OPT_TYPE_CONST, {.i64=AVCOL_TRC_ARIB_STD_B67}, INT_MIN, INT_MAX, STATIC, .unit = "color_trc"}, + {"rotate", "rotate the input clockwise", OFFSET(rotation), AV_OPT_TYPE_INT, {.i64=PL_ROTATION_0}, PL_ROTATION_0, PL_ROTATION_360, DYNAMIC, .unit = "rotation"}, + {"0", NULL, 0, AV_OPT_TYPE_CONST, {.i64=PL_ROTATION_0}, .flags = STATIC, .unit = "rotation"}, + {"90", NULL, 0, AV_OPT_TYPE_CONST, {.i64=PL_ROTATION_90}, .flags = STATIC, .unit = "rotation"}, + {"180", NULL, 0, AV_OPT_TYPE_CONST, {.i64=PL_ROTATION_180}, .flags = STATIC, .unit = "rotation"}, + {"270", NULL, 0, AV_OPT_TYPE_CONST, {.i64=PL_ROTATION_270}, .flags = STATIC, .unit = "rotation"}, + {"360", NULL, 0, AV_OPT_TYPE_CONST, {.i64=PL_ROTATION_360}, .flags = STATIC, .unit = "rotation"}, + { "upscaler", "Upscaler function", OFFSET(upscaler), AV_OPT_TYPE_STRING, {.str = "spline36"}, .flags = DYNAMIC }, { "downscaler", "Downscaler function", OFFSET(downscaler), AV_OPT_TYPE_STRING, {.str = "mitchell"}, .flags = DYNAMIC }, { "frame_mixer", "Frame mixing function", OFFSET(frame_mixer), AV_OPT_TYPE_STRING, {.str = "none"}, .flags = DYNAMIC }, ++++++ ffmpeg-7-CVE-2026-66036.patch ++++++ >From 62294b6a8ad2370e1435bb9985ebe6b53be14c2b Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 13:05:33 +0200 Subject: [PATCH] avfilter/vf_hqdn3d: support dynamic frame sizes (cherry picked from commit 5d7112c60e6f0f0742ce47d448e6da0718a70f4c) --- libavfilter/avfilter.c | 3 ++- libavfilter/vf_hqdn3d.c | 21 ++++++++++++++------- 2 files changed, 16 insertions(+), 8 deletions(-) diff a/libavfilter/avfilter.c b/libavfilter/avfilter.c --- a/libavfilter/avfilter.c +++ b/libavfilter/avfilter.c @@ -1033,7 +1033,8 @@ strcmp(link->dst->filter->name, "idet") && strcmp(link->dst->filter->name, "null") && strcmp(link->dst->filter->name, "scale") && - strcmp(link->dst->filter->name, "libplacebo")) { + strcmp(link->dst->filter->name, "libplacebo") && + strcmp(link->dst->filter->name, "hqdn3d")) { av_assert1(frame->format == link->format); av_assert1(frame->width == link->w); av_assert1(frame->height == link->h); diff a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c --- a/libavfilter/vf_hqdn3d.c +++ b/libavfilter/vf_hqdn3d.c @@ -315,21 +315,28 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) AVFrame *out; int direct = av_frame_is_writable(in) && !ctx->is_disabled; ThreadData td; - int ret[3]; + int err, ret[3]; - if (in->format != s->format || - in->width != s->width || - in->height != s->height) { - av_log(ctx, AV_LOG_ERROR, - "Frame size or format changed without filter graph reinitialization\n"); + if (in->format != s->format) { av_frame_free(&in); return AVERROR(EINVAL); } + if (in->width != s->width || in->height != s->height) { + inlink->w = in->width; + inlink->h = in->height; + if ((err = config_input(inlink)) < 0) { + av_frame_free(&in); + return err; + } + outlink->w = in->width; + outlink->h = in->height; + } + if (direct) { out = in; } else { - out = ff_get_video_buffer(outlink, outlink->w, outlink->h); + out = ff_get_video_buffer(outlink, in->width, in->height); if (!out) { av_frame_free(&in); return AVERROR(ENOMEM); -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-66037.patch ++++++ >From f15e730cd225763bbae68614af777560aeb449dd Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 28 Jun 2026 22:05:28 +0200 Subject: [PATCH] avformat/iamf_parse: check count_label against the available bytes Fixes: unbounded allocation / denial of service Fixes: tP59h4cpaFyg Fixes: 4ee05182b7 (avformat: Immersive Audio Model and Formats demuxer) Found-by: Adrian Junge (vurlo) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 86708357d126af84c16f80d9c57335d1e8c845c5) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/iamf_parse.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/libavformat/iamf_parse.c b/libavformat/iamf_parse.c index d74a8677d6..4c2df2c9e6 100644 --- a/libavformat/iamf_parse.c +++ b/libavformat/iamf_parse.c @@ -1009,6 +1009,11 @@ static int mix_presentation_obu(void *s, IAMFContext *c, AVIOContext *pb, int le mix_presentation->cmix = mix; mix_presentation->count_label = ffio_read_leb(pbc); + if (mix_presentation->count_label > len - avio_tell(pbc)) { + mix_presentation->count_label = 0; + ret = AVERROR_INVALIDDATA; + goto fail; + } mix_presentation->language_label = av_calloc(mix_presentation->count_label, sizeof(*mix_presentation->language_label)); if (!mix_presentation->language_label) { -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-66038.patch ++++++ >From e7cbfd1c507b57a806a5825b87d609963e862c8c Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 28 Jun 2026 19:04:07 +0200 Subject: [PATCH] avcodec/lcldec: zero the not-decoded tail to avoid heap disclosure Fixes: use of uninitialized memory Fixes: CsNDKB1K1U0C Fixes: e2c3aa8e2b (avcodec/lcldec: More space for rgb24) Found-by: Adrian Junge (vurlo) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/lcldec.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/libavcodec/lcldec.c b/libavcodec/lcldec.c index 29b1d85be3..5023243017 100644 --- a/libavcodec/lcldec.c +++ b/libavcodec/lcldec.c @@ -120,6 +120,9 @@ static unsigned int mszh_decomp(const unsigned char * srcptr, int srclen, unsign } } + if (destptr < destptr_end) + memset(destptr, 0, destptr_end - destptr); + return destptr - destptr_bak; } @@ -153,8 +156,11 @@ static int zlib_decomp(AVCodecContext *avctx, const uint8_t *src, int src_len, i if (expected != (unsigned int)zstream->total_out) { av_log(avctx, AV_LOG_ERROR, "Decoded size differs (%d != %lu)\n", expected, zstream->total_out); - if (expected > (unsigned int)zstream->total_out) + if (expected > (unsigned int)zstream->total_out) { + memset(c->decomp_buf + offset + zstream->total_out, 0, + c->decomp_size - offset - zstream->total_out); return (unsigned int)zstream->total_out; + } return AVERROR_UNKNOWN; } return zstream->total_out; -- 2.54.0 ++++++ ffmpeg-7-CVE-2026-66039.patch ++++++ >From aafb5c655edc76a753275c383ebb139feb032718 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Mon, 29 Jun 2026 01:16:44 +0200 Subject: [PATCH] avcodec/mace: reject sample counts that overflow int Fixes: heap buffer overflow Fixes: FmXBI2dbgvgD Fixes: 0eea212943544d40f99b05571aa7159d78667154 (Add avcodec_decode_audio4().) Found-by: Adrian Junge (vurlo) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/mace.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/libavcodec/mace.c b/libavcodec/mace.c index 299e5f5cfe..87e802684a 100644 --- a/libavcodec/mace.c +++ b/libavcodec/mace.c @@ -252,7 +252,10 @@ static int mace_decode_frame(AVCodecContext *avctx, AVFrame *frame, } /* get output buffer */ - frame->nb_samples = 3 * (buf_size << (1 - is_mace3)) / channels; + int64_t nb_samples = 3 * ((int64_t)buf_size << (1 - is_mace3)) / channels; + if (nb_samples > INT_MAX) + return AVERROR_INVALIDDATA; + frame->nb_samples = nb_samples; if ((ret = ff_get_buffer(avctx, frame, 0)) < 0) return ret; samples = (int16_t **)frame->extended_data; -- 2.54.0 ++++++ ffmpeg-7-CVE-2026-66041.patch ++++++ >From 4da9812e25894fb51d62a8875cfa8eb39b5e20f5 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 28 Jun 2026 15:33:38 +0200 Subject: [PATCH] avfilter/vf_quirc: resize the quirc buffers when the input size changes Fixes: out of array access Fixes: JbvzNObhorBp Fixes: 030e140145 (lavfi: add quirc filter) Found-by: Adrian Junge (vurlo) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_quirc.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/libavfilter/vf_quirc.c b/libavfilter/vf_quirc.c index 59dc84caa8..d2ba48e7bc 100644 --- a/libavfilter/vf_quirc.c +++ b/libavfilter/vf_quirc.c @@ -36,6 +36,7 @@ typedef struct QuircContext { const AVClass *class; struct quirc *quirc; + int width, height; } QuircContext; static av_cold int init(AVFilterContext *ctx) @@ -67,6 +68,8 @@ static int config_input(AVFilterLink *inlink) if (err == -1) { return AVERROR(ENOMEM); } + quirc->width = inlink->w; + quirc->height = inlink->h; return 0; } @@ -80,6 +83,15 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *frame) int codes_count; uint8_t *image; + if (quirc->width != inlink->w || quirc->height != inlink->h) { + if (quirc_resize(quirc->quirc, inlink->w, inlink->h) < 0) { + av_frame_free(&frame); + return AVERROR(ENOMEM); + } + quirc->width = inlink->w; + quirc->height = inlink->h; + } + /* copy input image to quirc buffer */ image = quirc_begin(quirc->quirc, NULL, NULL); av_image_copy_plane(image, inlink->w, -- 2.54.0 ++++++ ffmpeg-7-CVE-2026-70628.patch ++++++ >From 02fc47e13f903768b75f7985a2706a6223ab4506 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:49:11 +0200 Subject: [PATCH] avcodec/dvbsub_parser: avoid signed overflow in the capacity check Fixes: signed integer overflow Fixes: out of array access Fixes: poc.wtv Fixes: fJeEU9JwKwsR Found-by: Adrian Junge (vurlo) (cherry picked from commit 93f2a525ec6c7b467bae68322720d10188fc6e30) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/dvbsub_parser.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/dvbsub_parser.c b/libavcodec/dvbsub_parser.c index 4527e4dd75..a93f39bfe0 100644 --- a/libavcodec/dvbsub_parser.c +++ b/libavcodec/dvbsub_parser.c @@ -104,7 +104,7 @@ static int dvbsub_parse(AVCodecParserContext *s, } } - if (buf_size - buf_pos + pc->packet_index > PARSE_BUF_SIZE) + if (buf_size - buf_pos > PARSE_BUF_SIZE - pc->packet_index) return buf_size; /* if not currently in a packet, pass data */ -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-70629.patch ++++++ >From a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:03 +0200 Subject: [PATCH] avcodec/rscc: do not leave uninitilized data when the input is too short Fixes: use of uninitialized memory Fixes: rscc_short_deflate_heap_disclosure.avi Fixes: plB80py3i3Bu Found-by: Adrian Junge (vurlo) (cherry picked from commit cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rscc.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/libavcodec/rscc.c b/libavcodec/rscc.c index 3715e1c6d4..5fde30ec35 100644 --- a/libavcodec/rscc.c +++ b/libavcodec/rscc.c @@ -311,6 +311,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, AVFrame *frame, ret = AVERROR_UNKNOWN; goto end; } + if (len < pixel_size) { + av_log(avctx, AV_LOG_WARNING, "Deflated %lu bytes, but %d are needed\n", + len, pixel_size); + memset(ctx->inflated_buf + len, 0, pixel_size - len); + pixel_size = len; + } pixels = ctx->inflated_buf; } -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-70630.patch ++++++ >From c22667d0fd7916a33fd3e79685b7246fc48f1a62 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:41 +0200 Subject: [PATCH] avcodec/screenpresso: reject deflate output shorter than the frame Fixes: use of uninitialized memory Fixes: screenpresso_short_zlib_heap_disclosure.avi Fixes: ksUBwBOjJodq Found-by: Adrian Junge (vurlo) (cherry picked from commit 705890061467ad550ecc1dad5eea07f28ccfb43e) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/screenpresso.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c index b27154991c..5864253d41 100644 --- a/libavcodec/screenpresso.c +++ b/libavcodec/screenpresso.c @@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame, return AVERROR_INVALIDDATA; } + /* Codec has aligned strides */ + src_linesize = FFALIGN(avctx->width * component_size, 4); + /* Inflate the frame after the 2 byte header */ ret = uncompress(ctx->inflated_buf, &length, avpkt->data + 2, avpkt->size - 2); @@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame, av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret); return AVERROR_UNKNOWN; } + if (length < src_linesize * avctx->height) { + av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n", + length, src_linesize * avctx->height); + return AVERROR_INVALIDDATA; + } ret = ff_reget_buffer(avctx, ctx->current, 0); if (ret < 0) return ret; - /* Codec has aligned strides */ - src_linesize = FFALIGN(avctx->width * component_size, 4); - /* When a keyframe is found, copy it (flipped) */ if (keyframe) av_image_copy_plane(ctx->current->data[0] + -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-70631.patch ++++++ >From 3c287af3affe1286350faa69c02bcc5d49de18bb Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:41 +0200 Subject: [PATCH] avcodec/tiff: reject inflate output shorter than the strip Fixes: use of uninitialized memory Fixes: tiff_short_deflate_heap_disclosure.tiff Fixes: 1cRIkpUVMQtn Found-by: Adrian Junge (vurlo) (cherry picked from commit 2f234ea34c81288e3840fca632dd16481d8de39f) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/tiff.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c index 8a179f0fd0..b8ce7b0b55 100644 --- a/libavcodec/tiff.c +++ b/libavcodec/tiff.c @@ -526,6 +526,7 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, uint8_t *dst, int stride uint8_t *zbuf; unsigned long outlen; int ret, line; + int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : lines; outlen = width * lines; zbuf = av_malloc(outlen); if (!zbuf) @@ -545,6 +546,12 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, uint8_t *dst, int stride av_free(zbuf); return AVERROR_UNKNOWN; } + if (outlen < (unsigned long)width * rows) { + av_log(s->avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %lu are needed\n", + outlen, (unsigned long)width * rows); + av_free(zbuf); + return AVERROR_INVALIDDATA; + } src = zbuf; for (line = 0; line < lines; line++) { if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) { @@ -592,6 +599,7 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, uint8_t *dst, int stride { uint64_t outlen = width * (uint64_t)lines; int ret, line; + int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : lines; uint8_t *buf = av_malloc(outlen); if (!buf) return AVERROR(ENOMEM); @@ -610,6 +618,12 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, uint8_t *dst, int stride av_free(buf); return AVERROR_UNKNOWN; } + if (outlen < (uint64_t)width * rows) { + av_log(s->avctx, AV_LOG_ERROR, "Uncompressed %"PRIu64" bytes, but %"PRIu64" are needed\n", + outlen, (uint64_t)width * rows); + av_free(buf); + return AVERROR_INVALIDDATA; + } src = buf; for (line = 0; line < lines; line++) { if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) { -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-70632.patch ++++++ >From 16b2049d4d5222db6cd7c031409058571c94f6a9 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:53:16 +0200 Subject: [PATCH] avcodec/cfhd: reject transform-2 output wider than the plane Fixes: out of array access Fixes: cfhd_transform2_output_width_oob.avi Fixes: MimvoaEVpKow Found-by: Adrian Junge (vurlo) (cherry picked from commit db05df9d135fb56a4babb836d5e9f5c1d984e087) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/cfhd.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/libavcodec/cfhd.c b/libavcodec/cfhd.c index 4d430e32ef..128362ac62 100644 --- a/libavcodec/cfhd.c +++ b/libavcodec/cfhd.c @@ -1224,7 +1224,7 @@ finish: if (lowpass_height > s->plane[plane].band[4][1].a_height || lowpass_width > s->plane[plane].band[4][1].a_width || !highpass_stride || s->plane[plane].band[4][1].width > s->plane[plane].band[4][1].a_width || - lowpass_width < 3 || lowpass_height < 3) { + lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > s->plane[plane].width) { av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n"); ret = AVERROR(EINVAL); goto end; @@ -1345,7 +1345,7 @@ finish: if (lowpass_height > s->plane[plane].band[4][1].a_height || lowpass_width > s->plane[plane].band[4][1].a_width || s->plane[plane].band[4][1].width > s->plane[plane].band[4][1].a_width || - lowpass_width < 3 || lowpass_height < 3) { + lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > s->plane[plane].width) { av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n"); ret = AVERROR(EINVAL); goto end; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-75141.patch ++++++ >From acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:56 +0000 Subject: [PATCH] avformat/hevc: reject hvcC NAL arrays that overflow the 16-bit count numNalus is uint16_t; a crafted hvcC declaring >65535 NAL units of one type wraps it to 0 and then writes nal[-1]. Reject before the count can wrap. Reachable by remuxing a crafted file with -c copy. Fixes: integer overflow Fixes: out of array access --- libavformat/hevc.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/libavformat/hevc.c b/libavformat/hevc.c index c9ee11f36c..678a9e2206 100644 --- a/libavformat/hevc.c +++ b/libavformat/hevc.c @@ -844,6 +844,9 @@ static int hvcc_array_add_nal_unit(const uint8_t *nal_buf, uint32_t nal_size, int ret; uint16_t numNalus = array->numNalus; + if (numNalus >= UINT16_MAX) + return AVERROR_INVALIDDATA; + ret = av_reallocp_array(&array->nal, numNalus + 1, sizeof(*array->nal)); if (ret < 0) return ret; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-75142.patch ++++++ >From 9d786e4b5e9b8482651928574de33772aeee7be1 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/mpegenc: reject stream counts that overflow the system header put_system_header() writes 12 + 3*N bytes after the pack header into a fixed 128-byte stack buffer, but is handed a PutBitContext sized past the real buffer, so its own bounds check never fires; ~35+ streams overflow the stack. Reject at mux init when the system header would not fit. Fixes: out of array access Fixes: many.mkv --- libavformat/mpegenc.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/libavformat/mpegenc.c b/libavformat/mpegenc.c index 128dfe2885..cea91d80da 100644 --- a/libavformat/mpegenc.c +++ b/libavformat/mpegenc.c @@ -473,6 +473,16 @@ static av_cold int mpeg_mux_init(AVFormatContext *ctx) if (!stream->fifo) return AVERROR(ENOMEM); } + + /* The system header is emitted, right after the pack header (which is at + * most 14 bytes), into the fixed 128-byte buffer used by flush_packet(). + * Reject configurations whose system header would not fit. */ + if (get_system_header_size(ctx) > 128 - 14) { + av_log(ctx, AV_LOG_ERROR, + "Too many streams to fit the MPEG program stream system header\n"); + return AVERROR(EINVAL); + } + bitrate = 0; audio_bitrate = 0; video_bitrate = 0; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-75143.patch ++++++ >From 1c10bcc2e17255dacb717a25ab3db142ce390602 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/librist: honor the caller buffer size in librist_read librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination (e.g. via the async: wrapper). Clamp the copy to the caller-provided buffer size. Fixes: out of array access --- libavformat/librist.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/librist.c b/libavformat/librist.c index 9669d5b5df..3c4b5e3e5b 100644 --- a/libavformat/librist.c +++ b/libavformat/librist.c @@ -226,7 +226,7 @@ static int librist_read(URLContext *h, uint8_t *buf, int size) } } - size = data_block->payload_len; + size = FFMIN(data_block->payload_len, size); memcpy(buf, data_block->payload, size); out_free: rist_receiver_data_block_free2(&data_block); -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-75144.patch ++++++ >From 1cdeb3c4e7f1f8566d846b9b451e01c376398818 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer send_packet() copied an input-derived unit/fragment size into the fixed rtp_ctx->buf with no bound, overflowing it for a crafted Dirac unit even at the default packet size. Reject units that do not fit in max_payload_size. Fixes: out of array access --- libavformat/rtpenc_vc2hq.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c index cf548191d2..3b7147dfe2 100644 --- a/libavformat/rtpenc_vc2hq.c +++ b/libavformat/rtpenc_vc2hq.c @@ -33,16 +33,23 @@ #define DIRAC_PIC_NR_SIZE 4 #define DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT 0xEC -static void send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m) +static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m) { RTPMuxContext *rtp_ctx = ctx->priv_data; + if (size < 0 || + size > rtp_ctx->max_payload_size - RTP_VC2HQ_PL_HEADER_SIZE - info_hdr_size) { + av_log(ctx, AV_LOG_ERROR, "VC-2 data unit too large for RTP payload buffer\n"); + return AVERROR_INVALIDDATA; + } + AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */ AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: interlaced, second field */ AV_WB8 (&rtp_ctx->buf[3], parse_code); if (size > 0) memcpy(&rtp_ctx->buf[4 + info_hdr_size], buf, size); ff_rtp_send_data(ctx, rtp_ctx->buf, RTP_VC2HQ_PL_HEADER_SIZE + info_hdr_size + size, rtp_m); + return 0; } static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int interlaced) @@ -85,7 +92,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int AV_WB16(&info_hdr[ 6], size_scaler); AV_WB16(&info_hdr[ 8], frag_len); AV_WB16(&info_hdr[10], 0 /* nr. of slices */); - send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, interlaced, second_field, 0); + if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, interlaced, second_field, 0) < 0) + return AVERROR_INVALIDDATA; buf += frag_len; size -= frag_len; @@ -97,7 +105,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int AV_WB16(&info_hdr[14], 0 /* slice y */); size -= frag_len; - send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, interlaced, second_field, size > 0 ? 0 : 1); + if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, interlaced, second_field, size > 0 ? 0 : 1) < 0) + return AVERROR_INVALIDDATA; buf += frag_len; } return 0; -- 2.49.0 ++++++ ffmpeg-7-CVE-2026-75146.patch ++++++ >From 65b0dab903e5975e036b30ecc58f5935d4f151e0 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/dashdec: reject a negative fragment index A live manifest whose startNumber decreases across a refresh drives cur_seq_no negative in move_segments(); get_current_fragment() only checked the upper bound before indexing fragments[]. Add a lower-bound check and clamp the negative delta at its source. Fixes: out of array read --- libavformat/dashdec.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff a/libavformat/dashdec.c b/libavformat/dashdec.c --- a/libavformat/dashdec.c +++ b/libavformat/dashdec.c @@ -1488,8 +1488,11 @@ static void move_segments(struct represe free_fragment_list(rep_dest); if (rep_src->start_number > (rep_dest->start_number + rep_dest->n_fragments)) rep_dest->cur_seq_no = 0; - else + else { rep_dest->cur_seq_no += rep_src->start_number - rep_dest->start_number; + if (rep_dest->cur_seq_no < 0) + rep_dest->cur_seq_no = 0; + } rep_dest->fragments = rep_src->fragments; rep_dest->n_fragments = rep_src->n_fragments; rep_dest->parent = rep_src->parent; @@ -1608,7 +1611,7 @@ static struct fragment *get_current_frag DASHContext *c = pls->parent->priv_data; while (( !ff_check_interrupt(c->interrupt_callback)&& pls->n_fragments > 0)) { - if (pls->cur_seq_no < pls->n_fragments) { + if (pls->cur_seq_no >= 0 && pls->cur_seq_no < pls->n_fragments) { seg_ptr = pls->fragments[pls->cur_seq_no]; seg = av_mallocz(sizeof(struct fragment)); if (!seg) {
