Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package ffmpeg-7 for openSUSE:Factory 
checked in at 2026-09-02 17:00:31
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/ffmpeg-7 (Old)
 and      /work/SRC/openSUSE:Factory/.ffmpeg-7.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "ffmpeg-7"

Wed Sep  2 17:00:31 2026 rev:31 rq:1375210 version:7.1.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/ffmpeg-7/ffmpeg-7.changes        2026-07-26 
16:37:26.664957826 +0200
+++ /work/SRC/openSUSE:Factory/.ffmpeg-7.new.1265/ffmpeg-7.changes      
2026-09-02 17:00:35.052844676 +0200
@@ -1,0 +2,196 @@
+Mon Aug 28 05:22:38 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75147.patch:
+  Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU
+  size in the keyframe search loop.
+  (CVE-2026-75147, bsc#1276413)
+
+-------------------------------------------------------------------
+Mon Aug 28 04:47:54 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75146.patch:
+  Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative
+  fragment index.
+  (CVE-2026-75146, bsc#1276412)
+
+-------------------------------------------------------------------
+Mon Aug 28 04:02:17 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75145.patch:
+  Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow
+  the OBU size to (long).
+  (CVE-2026-75145, bsc#1276411)
+
+-------------------------------------------------------------------
+Mon Aug 28 03:34:50 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75144.patch:
+  Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data
+  units larger than the RTP payload buffer.
+  (CVE-2026-75144, bsc#1276410)
+
+-------------------------------------------------------------------
+Mon Aug 28 03:17:21 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75143.patch:
+  Backport 1c10bcc2 from upstream, avformat/librist: honor the caller
+  buffer size in librist_read.
+  (CVE-2026-75143, bsc#1276409)
+
+-------------------------------------------------------------------
+Mon Aug 28 02:58:12 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75142.patch:
+  Backport 9d786e4b from upstream, avformat/mpegenc: reject stream
+  counts that overflow the system header.
+  (CVE-2026-75142, bsc#1276408)
+
+-------------------------------------------------------------------
+Mon Aug 28 02:44:56 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-75141.patch:
+  Backport acf5d7cd from upstream, avformat/hevc: reject hvcC
+  NAL arrays that overflow the 16-bit count.
+  (CVE-2026-75141, bsc#1276407)
+
+-------------------------------------------------------------------
+Wed Aug 14 09:44:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-70632.patch:
+  Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2
+  output wider than the plane.
+  (CVE-2026-70632, bsc#1274289)
+
+-------------------------------------------------------------------
+Wed Aug 14 08:27:41 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-70631.patch:
+  Backport 3c287af3 from upstream, avcodec/tiff: reject inflate
+  output shorter than the strip.
+  (CVE-2026-70631, bsc#1274287)
+
+-------------------------------------------------------------------
+Wed Aug 14 07:58:24 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-70630.patch:
+  Backport c22667d0 from upstream, avcodec/screenpresso: reject
+  deflate output shorter than the frame.
+  (CVE-2026-70630, bsc#1274282)
+
+-------------------------------------------------------------------
+Wed Aug 14 07:22:18 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-70629.patch:
+  Backport a5fe21a1 from upstream, avcodec/rscc: do not leave
+  uninitilized data when the input is too short.
+  (CVE-2026-70629, bsc#1274270)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:52:11 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-70628.patch:
+  Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid
+  signed overflow in the capacity check.
+  (CVE-2026-70628, bsc#1274268)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:41:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-66037.patch:
+  Backport f15e730c from upstream, avformat/iamf_parse: check
+  count_label against the available bytes.
+  (CVE-2026-66037, bsc#1272764)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:28:33 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-66036.patch:
+  Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support
+  dynamic frame sizes.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:09:17 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-66036-shim02.patch
+  Backport 4f623b4c from upstream, avfilter/vf_libplacebo: implement
+  rotation option. This patch is for facilitate ffmpeg-CVE-2026-66036.patch.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 05:51:42 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-66036-shim01.patch
+  Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject
+  unsupported frame parameter changes. This patch is for facilitate
+  ffmpeg-CVE-2026-66036.patch.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 05:31:22 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-65706.patch:
+  Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the
+  temp row buffer for the widest plane.
+  (CVE-2026-65706, bsc#1272762)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:56:09 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-65705.patch:
+  Backport 30a52276 from upstream, avfilter/vf_floodfill: remove
+  unneeded variables.
+  (CVE-2026-65705, bsc#1272761)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:31:19 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-65704.patch:
+  Backport 52f7983f from upstream, avformat/ty: don't let the Series2
+  AC3 trim underflow the packet size.
+  (CVE-2026-65704, bsc#1272760)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:02:11 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-65703.patch:
+  Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference
+  frame before reallocating on size change.
+  (CVE-2026-65703, bsc#1272759)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:46:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-64834.patch:
+  Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF
+  objects smaller than their header.
+  (CVE-2026-64834, bsc#1272757)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:33:14 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-64833.patch:
+  Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS
+  core_size against the packet size in the HD path.
+  (CVE-2026-64833, bsc#1272755)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:28:13 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-7-CVE-2026-58049.patch:
+  Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit
+  DLTA accesses stay within the row.
+  (CVE-2026-58049, bsc#1269550)
+
+-------------------------------------------------------------------
+Thu Jul 30 02:39:03 UTC 2026 - Xiaoguang Wang <[email protected]>
+
+- Add CVE patches:
+  ffmpeg-7-CVE-2026-64835.patch: (CVE-2026-64835, bsc#1272758)
+  ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754)
+  ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752)
+  ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768)
+  ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765)
+  ffmpeg-7-CVE-2026-66041.patch: (CVE-2026-66041, bsc#1272767)
+
+-------------------------------------------------------------------
@@ -12,0 +209,4 @@
+  * avcodec/magicyuv: reject slice_height misaligned with chroma vshift.
+    (CVE-2026-8461, bsc#1269490)
+  * avcodec/magicyuv: Expand the s->interlaced slice-height sanity check.
+    (CVE-2026-8461, bsc#1269490)
@@ -122,0 +323,2 @@
+  * avformat/hls: Be more picky on extensions.
+    (CVE-2023-6602, bsc#1220546, CVE-2023-6604, bsc#1220549)
@@ -216,0 +419,4 @@
+  * avcodec/vp9: Fix race when attaching side-data for show-existing frame. 
(commit: 0ba0585)
+    (CVE-2024-36615, bsc#1234017)
+  * lavc/vp9: Fix regression introduced in 0ba0585.
+    (CVE-2024-36615, bsc#1234017)
@@ -284,0 +491,3 @@
+  * avcodec/ppc/vp8dsp_altivec: Fix out-of-bounds access 
h_subpel_filters_inner[i] and
+    h_subpel_filters_outer[i / 2] belong together and the former allows the 
range 0..6.
+    (CVE-2024-35367, bsc#1234029)

New:
----
  ffmpeg-7-CVE-2026-58049.patch
  ffmpeg-7-CVE-2026-64830.patch
  ffmpeg-7-CVE-2026-64832.patch
  ffmpeg-7-CVE-2026-64833.patch
  ffmpeg-7-CVE-2026-64834.patch
  ffmpeg-7-CVE-2026-64835.patch
  ffmpeg-7-CVE-2026-65703.patch
  ffmpeg-7-CVE-2026-65704.patch
  ffmpeg-7-CVE-2026-65705.patch
  ffmpeg-7-CVE-2026-65706.patch
  ffmpeg-7-CVE-2026-66036-shim01.patch
  ffmpeg-7-CVE-2026-66036-shim02.patch
  ffmpeg-7-CVE-2026-66036.patch
  ffmpeg-7-CVE-2026-66037.patch
  ffmpeg-7-CVE-2026-66038.patch
  ffmpeg-7-CVE-2026-66039.patch
  ffmpeg-7-CVE-2026-66041.patch
  ffmpeg-7-CVE-2026-70628.patch
  ffmpeg-7-CVE-2026-70629.patch
  ffmpeg-7-CVE-2026-70630.patch
  ffmpeg-7-CVE-2026-70631.patch
  ffmpeg-7-CVE-2026-70632.patch
  ffmpeg-7-CVE-2026-75141.patch
  ffmpeg-7-CVE-2026-75142.patch
  ffmpeg-7-CVE-2026-75143.patch
  ffmpeg-7-CVE-2026-75144.patch
  ffmpeg-7-CVE-2026-75146.patch

----------(New B)----------
  New:
- Add ffmpeg-7-CVE-2026-58049.patch:
  Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit
  New:  ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754)
  ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752)
  ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768)
  New:  ffmpeg-7-CVE-2026-64835.patch: (CVE-2026-64835, bsc#1272758)
  ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754)
  ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752)
  New:
- Add ffmpeg-7-CVE-2026-64833.patch:
  Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS
  New:
- Add ffmpeg-7-CVE-2026-64834.patch:
  Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF
  New:- Add CVE patches:
  ffmpeg-7-CVE-2026-64835.patch: (CVE-2026-64835, bsc#1272758)
  ffmpeg-7-CVE-2026-64832.patch: (CVE-2026-64832, bsc#1272754)
  New:
- Add ffmpeg-7-CVE-2026-65703.patch:
  Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference
  New:
- Add ffmpeg-7-CVE-2026-65704.patch:
  Backport 52f7983f from upstream, avformat/ty: don't let the Series2
  New:
- Add ffmpeg-7-CVE-2026-65705.patch:
  Backport 30a52276 from upstream, avfilter/vf_floodfill: remove
  New:
- Add ffmpeg-7-CVE-2026-65706.patch:
  Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the
  New:
- Add ffmpeg-7-CVE-2026-66036-shim01.patch
  Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject
  New:
- Add ffmpeg-7-CVE-2026-66036-shim02.patch
  Backport 4f623b4c from upstream, avfilter/vf_libplacebo: implement
  New:
- Add ffmpeg-7-CVE-2026-66036.patch:
  Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support
  New:
- Add ffmpeg-7-CVE-2026-66037.patch:
  Backport f15e730c from upstream, avformat/iamf_parse: check
  New:  ffmpeg-7-CVE-2026-64830.patch: (CVE-2026-64830, bsc#1272752)
  ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768)
  ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765)
  New:  ffmpeg-7-CVE-2026-66038.patch: (CVE-2026-66038, bsc#1272768)
  ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765)
  ffmpeg-7-CVE-2026-66041.patch: (CVE-2026-66041, bsc#1272767)
  New:  ffmpeg-7-CVE-2026-66039.patch: (CVE-2026-66039, bsc#1272765)
  ffmpeg-7-CVE-2026-66041.patch: (CVE-2026-66041, bsc#1272767)
  New:
- Add ffmpeg-7-CVE-2026-70628.patch:
  Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid
  New:
- Add ffmpeg-7-CVE-2026-70629.patch:
  Backport a5fe21a1 from upstream, avcodec/rscc: do not leave
  New:
- Add ffmpeg-7-CVE-2026-70630.patch:
  Backport c22667d0 from upstream, avcodec/screenpresso: reject
  New:
- Add ffmpeg-7-CVE-2026-70631.patch:
  Backport 3c287af3 from upstream, avcodec/tiff: reject inflate
  New:
- Add ffmpeg-7-CVE-2026-70632.patch:
  Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2
  New:
- Add ffmpeg-7-CVE-2026-75141.patch:
  Backport acf5d7cd from upstream, avformat/hevc: reject hvcC
  New:
- Add ffmpeg-7-CVE-2026-75142.patch:
  Backport 9d786e4b from upstream, avformat/mpegenc: reject stream
  New:
- Add ffmpeg-7-CVE-2026-75143.patch:
  Backport 1c10bcc2 from upstream, avformat/librist: honor the caller
  New:
- Add ffmpeg-7-CVE-2026-75144.patch:
  Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data
  New:
- Add ffmpeg-7-CVE-2026-75146.patch:
  Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ ffmpeg-7.spec ++++++
--- /var/tmp/diff_new_pack.pkjLuE/_old  2026-09-02 17:00:36.362889679 +0200
+++ /var/tmp/diff_new_pack.pkjLuE/_new  2026-09-02 17:00:36.364889747 +0200
@@ -120,6 +120,34 @@
 Patch5:         work-around-abi-break.patch
 Patch6:         ffmpeg-chromium.patch
 Patch7:         
11013-avcodec-decode-clean-up-if-get_hw_frames_parameters-.patch
+Patch8:         ffmpeg-7-CVE-2026-64835.patch
+Patch9:         ffmpeg-7-CVE-2026-64832.patch
+Patch10:        ffmpeg-7-CVE-2026-64830.patch
+Patch11:        ffmpeg-7-CVE-2026-66038.patch
+Patch12:        ffmpeg-7-CVE-2026-66039.patch
+Patch13:        ffmpeg-7-CVE-2026-66041.patch
+Patch14:        ffmpeg-7-CVE-2026-58049.patch
+Patch15:        ffmpeg-7-CVE-2026-64833.patch
+Patch16:        ffmpeg-7-CVE-2026-64834.patch
+Patch17:        ffmpeg-7-CVE-2026-65703.patch
+Patch18:        ffmpeg-7-CVE-2026-65704.patch
+Patch19:        ffmpeg-7-CVE-2026-65705.patch
+Patch20:        ffmpeg-7-CVE-2026-65706.patch
+Patch21:        ffmpeg-7-CVE-2026-66036-shim01.patch
+Patch22:        ffmpeg-7-CVE-2026-66036-shim02.patch
+Patch23:        ffmpeg-7-CVE-2026-66036.patch
+Patch24:        ffmpeg-7-CVE-2026-66037.patch
+Patch25:        ffmpeg-7-CVE-2026-70628.patch
+Patch26:        ffmpeg-7-CVE-2026-70629.patch
+Patch27:        ffmpeg-7-CVE-2026-70630.patch
+Patch28:        ffmpeg-7-CVE-2026-70631.patch
+Patch29:        ffmpeg-7-CVE-2026-70632.patch
+Patch30:        ffmpeg-7-CVE-2026-75141.patch
+Patch31:        ffmpeg-7-CVE-2026-75142.patch
+Patch32:        ffmpeg-7-CVE-2026-75143.patch
+Patch33:        ffmpeg-7-CVE-2026-75144.patch
+Patch34:        ffmpeg-7-CVE-2026-75146.patch
+# There is another Patch section further below!
 BuildRequires:  ladspa-devel
 BuildRequires:  libgsm-devel
 BuildRequires:  nasm
@@ -827,11 +855,18 @@
 Source3:        ffmpeg-7-rpmlintrc
 Source98:       http://ffmpeg.org/ffmpeg-devel.asc#/ffmpeg-7.keyring
 Patch1:         ffmpeg-arm6l.diff
+Patch2:         ffmpeg-new-coder-errors.diff
 Patch3:         ffmpeg-codec-choice.diff
 Patch4:         ffmpeg-4.2-dlopen-fdk_aac.patch
 Patch5:         work-around-abi-break.patch
 Patch6:         ffmpeg-chromium.patch
 Patch7:         
11013-avcodec-decode-clean-up-if-get_hw_frames_parameters-.patch
+Patch8:         ffmpeg-7-CVE-2026-64835.patch
+Patch9:         ffmpeg-7-CVE-2026-64832.patch
+Patch10:        ffmpeg-7-CVE-2026-64830.patch
+Patch11:        ffmpeg-7-CVE-2026-66038.patch
+Patch12:        ffmpeg-7-CVE-2026-66039.patch
+Patch13:        ffmpeg-7-CVE-2026-66041.patch
 BuildRequires:  c_compiler
 BuildRequires:  pkgconfig(openh264)
 Requires:       this-is-only-for-build-envs

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.pkjLuE/_old  2026-09-02 17:00:36.430892015 +0200
+++ /var/tmp/diff_new_pack.pkjLuE/_new  2026-09-02 17:00:36.433892118 +0200
@@ -1,5 +1,5 @@
-mtime: 1785070704
-commit: 4cffdaa568cc153bcc70385d4936802ac42a7ffc31db253b07f262d4242c72f6
-url: https://src.opensuse.org/jengelh/ffmpeg-7
-revision: master
+mtime: 1788290258
+commit: e96d75e8799e64715c1101a406dbc2157bed4b150731c6d6d8313c6e106fcf57
+url: https://src.opensuse.org/jengelh/ffmpeg
+revision: ff7
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-01 21:17:38.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ ffmpeg-7-CVE-2026-58049.patch ++++++
>From f8d7795dcca36a4dd412e89cbd83e3dfec1e0d81 Mon Sep 17 00:00:00 2001
From: Umar Pathan <[email protected]>
Date: Sun, 28 Jun 2026 23:02:52 +0200
Subject: [PATCH] avcodec/rasc: Check that 32-bit DLTA accesses stay within the
 row

Found-by: bikini (github.com/bikini/exploitarium)
Fixes: out of array access
Fixes: rowspill_128x1.avi / gen_rowspill_avi.py
Fixes: xGV79bIb7uAJ
(cherry picked from commit 11ff18a6c80187405fc492f9bb07ba9f2f663f76)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/rasc.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/libavcodec/rasc.c b/libavcodec/rasc.c
index 5f956a9b2c..d784a44063 100644
--- a/libavcodec/rasc.c
+++ b/libavcodec/rasc.c
@@ -320,6 +320,11 @@ static int decode_move(AVCodecContext *avctx,
     return 0;
 }
 
+static inline int dlta_room(unsigned cx, unsigned w, unsigned bpp, unsigned 
need)
+{
+    return cx + need <= w * bpp;
+}
+
 #define NEXT_LINE                        \
     if (cx >= w * s->bpp) {              \
         cx = 0;                          \
@@ -418,6 +423,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 4:
             fill = bytestream2_get_byte(&dc);
             while (len > 0 && cy > 0) {
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx++;
@@ -427,6 +434,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 7:
             fill = bytestream2_get_le32(&dc);
             while (len > 0 && cy > 0) {
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx += 4;
@@ -443,6 +452,8 @@ static int decode_dlta(AVCodecContext *avctx,
             while (len > 0 && cy > 0) {
                 unsigned v0, v1;
 
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 v0 = AV_RL32(b2 + cx);
                 v1 = AV_RL32(b1 + cx);
                 AV_WL32(b2 + cx, v1);
@@ -454,6 +465,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 13:
             while (len > 0 && cy > 0) {
                 fill = bytestream2_get_le32(&dc);
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx += 4;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-64830.patch ++++++
>From dbd495f066a85ba96b17433f4306582aa37c3951 Mon Sep 17 00:00:00 2001
From: Pavel Kohout <[email protected]>
Date: Mon, 29 Jun 2026 23:30:41 +0200
Subject: [PATCH] avformat/vobsub: reuse subtitle streams and bound the stream
 count

Fixes: heap buffer overflow
Fixes: lqaO5R1BaZGO
Fixes: dbfe61100b (avformat/vobsub: fix several issues.)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/mpeg.c | 18 ++++++++++++++++--
 1 file changed, 16 insertions(+), 2 deletions(-)

diff --git a/libavformat/mpeg.c b/libavformat/mpeg.c
index ff5ced8107..29abe329b9 100644
--- a/libavformat/mpeg.c
+++ b/libavformat/mpeg.c
@@ -841,6 +841,20 @@ static int vobsub_read_header(AVFormatContext *s)
             }
 
             if (!st || st->id != stream_id) {
+                st = NULL;
+                for (i = 0; i < s->nb_streams; i++) {
+                    if (s->streams[i]->id == stream_id) {
+                        st = s->streams[i];
+                        break;
+                    }
+                }
+            }
+            if (!st) {
+                if (s->nb_streams >= FF_ARRAY_ELEMS(vobsub->q)) {
+                    av_log(s, AV_LOG_ERROR, "Maximum number of subtitle 
streams reached\n");
+                    ret = AVERROR_INVALIDDATA;
+                    goto end;
+                }
                 st = avformat_new_stream(s, NULL);
                 if (!st) {
                     ret = AVERROR(ENOMEM);
@@ -865,14 +879,14 @@ static int vobsub_read_header(AVFormatContext *s)
             timestamp = (hh*3600LL + mm*60LL + ss) * 1000LL + ms + delay;
             timestamp = av_rescale_q(timestamp, av_make_q(1, 1000), 
st->time_base);
 
-            sub = ff_subtitles_queue_insert(&vobsub->q[s->nb_streams - 1], "", 
0, 0);
+            sub = ff_subtitles_queue_insert(&vobsub->q[st->index], "", 0, 0);
             if (!sub) {
                 ret = AVERROR(ENOMEM);
                 goto end;
             }
             sub->pos = pos;
             sub->pts = timestamp;
-            sub->stream_index = s->nb_streams - 1;
+            sub->stream_index = st->index;
 
         } else if (!strncmp(line, "alt:", 4)) {
             const char *p = line + 4;
-- 
2.54.0


++++++ ffmpeg-7-CVE-2026-64832.patch ++++++
>From 4c6217477fc64305055b37d9d1d0d76d30e37f97 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Tue, 30 Jun 2026 00:24:07 +0200
Subject: [PATCH] avcodec/nvdec: don't double free the fdd-owned context on the
 sep_ref error path

Fixes: double free
Fixes: rpSz7v3yq2u8
Fixes: 72982f8cb5dad6252a14226d28128313eed4a5ff (avcodec/nvdec: add support for 
separate reference frame)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/nvdec.c | 6 +-----
 1 file changed, 1 insertion(+), 5 deletions(-)

Index: ffmpeg-7.1.5/libavcodec/nvdec.c
===================================================================
--- ffmpeg-7.1.5.orig/libavcodec/nvdec.c
+++ ffmpeg-7.1.5/libavcodec/nvdec.c
@@ -614,8 +614,7 @@ int ff_nvdec_start_frame_sep_ref(AVCodec
             cf->ref_idx_ref = ff_refstruct_pool_get(ctx->decoder_pool);
             if (!cf->ref_idx_ref) {
                 av_log(avctx, AV_LOG_ERROR, "No decoder surfaces left\n");
-                ret = AVERROR(ENOMEM);
-                goto fail;
+                return AVERROR(ENOMEM);
             }
         }
         cf->ref_idx = *cf->ref_idx_ref;
@@ -625,9 +624,6 @@ int ff_nvdec_start_frame_sep_ref(AVCodec
     }
 
     return 0;
-fail:
-    nvdec_fdd_priv_free(cf);
-    return ret;
 }
 
 int ff_nvdec_end_frame(AVCodecContext *avctx)

++++++ ffmpeg-7-CVE-2026-64833.patch ++++++
>From 385ac2fadcb4394ec4f65e5c4d3d24003e090f36 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Tue, 30 Jun 2026 00:11:50 +0200
Subject: [PATCH] avformat/spdifenc: bound DTS core_size against the packet
 size in the HD path

Fixes: out of array read
Fixes: yBSax492UIB9
Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 6f80e2765492700622596af720534cef33dd31b4)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/spdifenc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c
index ab3f73da0d..16eebda01c 100644
--- a/libavformat/spdifenc.c
+++ b/libavformat/spdifenc.c
@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket 
*pkt, int core_size,
              * (dtshd_fallback == 0) */
             ctx->dtshd_skip = 1;
     }
-    if (ctx->dtshd_skip && core_size) {
+    if (ctx->dtshd_skip && core_size && core_size <= pkt->size) {
         pkt_size = core_size;
         if (ctx->dtshd_fallback >= 0)
             --ctx->dtshd_skip;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-64834.patch ++++++
>From 3c441711a343ccf50196c70a3f0b554b52f8d9de Mon Sep 17 00:00:00 2001
From: Pavel Kohout <[email protected]>
Date: Tue, 30 Jun 2026 21:55:16 +0200
Subject: [PATCH] avformat/rtpdec_asf: reject ASF objects smaller than their
 header

Fixes: infinite loop
Fixes: MzWwJdpZF2Ls
Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet 
parsing.)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 11d5f475be95d22d5f0692220cc772b116abc632)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/rtpdec_asf.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c
index b3b346f3cc..f7fa69e27f 100644
--- a/libavformat/rtpdec_asf.c
+++ b/libavformat/rtpdec_asf.c
@@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len)
         uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid));
         int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2;
         if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) {
+            if (chunksize < sizeof(ff_asf_guid) + 8)
+                return -1;
             if (chunksize > end - p)
                 return -1;
             p += chunksize;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-64835.patch ++++++
>From 1836ef96846937a6cc2443698a693104f5c0b21e Mon Sep 17 00:00:00 2001
From: Pavel Kohout <[email protected]>
Date: Mon, 29 Jun 2026 23:46:16 +0200
Subject: [PATCH] avcodec/adx: sync decoder channel state on NEW_EXTRADATA

Fixes: out of array access
Fixes: heaNtmHvklpe
Fixes: 92396cee602320c714713ca2d93b53684ad57000 (avformat: add CRI AAX demuxer)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/adxdec.c | 5 +++++
 1 file changed, 5 insertions(+)

Index: ffmpeg-7.1.5/libavcodec/adxdec.c
===================================================================
--- ffmpeg-7.1.5.orig/libavcodec/adxdec.c
+++ ffmpeg-7.1.5/libavcodec/adxdec.c
@@ -172,6 +172,7 @@ static int adx_decode_frame(AVCodecConte
     new_extradata = av_packet_get_side_data(avpkt, AV_PKT_DATA_NEW_EXTRADATA,
                                             &new_extradata_size);
     if (new_extradata && new_extradata_size > 0) {
+        int old_channels = c->channels;
         int header_size;
         if ((ret = adx_decode_header(avctx, new_extradata,
                                      new_extradata_size, &header_size,
@@ -180,6 +181,10 @@ static int adx_decode_frame(AVCodecConte
             return AVERROR_INVALIDDATA;
         }
 
+        c->channels      = avctx->ch_layout.nb_channels;
+        c->header_parsed = 1;
+        if (old_channels != c->channels)
+            memset(c->prev, 0, sizeof(c->prev));
         c->eof = 0;
     }
 

++++++ ffmpeg-7-CVE-2026-65703.patch ++++++
>From 3b85fbe89025ea696988488358dfde41a09c53c5 Mon Sep 17 00:00:00 2001
From: Cloud-LHY <[email protected]>
Date: Fri, 10 Jul 2026 04:07:04 +0200
Subject: [PATCH] avcodec/tdsc: unref the reference frame before reallocating
 on size change

Fixes: out of array access
Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
Fixes: tdsc_resize_jpeg_oob.avi / 
tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
Fixes: p9xG4xGf9P7H
Fixes: HQL7a1WgTdHZ
Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS
Found-by: Adrian Junge (vurlo)
(cherry picked from commit fd3ee52fab34d98a95b787d0b5ff45685766200c)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/tdsc.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c
index ca9dd0f0a6..102b4ae966 100644
--- a/libavcodec/tdsc.c
+++ b/libavcodec/tdsc.c
@@ -485,11 +485,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int 
number_tiles)
             return ret;
         init_refframe = 1;
     }
-    ctx->refframe->width  = ctx->width  = w;
-    ctx->refframe->height = ctx->height = h;
+    ctx->width  = w;
+    ctx->height = h;
 
     /* Allocate the reference frame if not already done or on size change */
     if (init_refframe) {
+        av_frame_unref(ctx->refframe);
+        ctx->refframe->format = avctx->pix_fmt;
+        ctx->refframe->width  = w;
+        ctx->refframe->height = h;
         ret = av_frame_get_buffer(ctx->refframe, 0);
         if (ret < 0)
             return ret;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-65704.patch ++++++
>From 52f7983f15678c8a6065327760d7b6eb1c9c84ed Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Fri, 10 Jul 2026 04:07:35 +0200
Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the
 packet size

Fixes: negative-size-param
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)
(cherry picked from commit de771bd52774a52d45b0e2c82e56995a1ef40df7)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/ty.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/ty.c b/libavformat/ty.c
index 9be027fcca..842d97038c 100644
--- a/libavformat/ty.c
+++ b/libavformat/ty.c
@@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr 
*rec_hdr, AVPacket *pkt)
         if (ty->audio_type == TIVO_AUDIO_AC3 &&
                 ty->tivo_series == TIVO_SERIES2) {
             if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) {
-                pkt->size -= 2;
+                pkt->size -= FFMIN(pkt->size, 2);
                 ty->ac3_pkt_size = 0;
             } else {
                 ty->ac3_pkt_size += pkt->size;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-65705.patch ++++++
>From 30a52276f9dff60fe732d8bb8d463e587ff69c94 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 03:27:47 +0200
Subject: [PATCH] avfilter/vf_floodfill: remove unneeded variables

Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit f186c50cf53aec20e9a29059cb22ca3f2d59201c)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_floodfill.c | 35 ++++++++++++++++-------------------
 1 file changed, 16 insertions(+), 19 deletions(-)

diff a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
--- a/libavfilter/vf_floodfill.c
+++ b/libavfilter/vf_floodfill.c
@@ -39,7 +39,6 @@
     int d[4];
 
     int nb_planes;
-    int back, front;
     Points *points;
 
     int (*is_same)(const AVFrame *frame, int x, int y,
@@ -270,7 +269,6 @@
        }
     }
 
-    s->front = s->back = 0;
     s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points));
     if (!s->points)
         return AVERROR(ENOMEM);
@@ -293,6 +291,7 @@
     const int w = frame->width;
     const int h = frame->height;
     int i, ret;
+    int front = 0;
 
     if (is_inside(s->x, s->y, w, h)) {
         s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
@@ -310,9 +309,9 @@
             goto end;
 
         if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) {
-            s->points[s->front].x = s->x;
-            s->points[s->front].y = s->y;
-            s->front++;
+            s->points[front].x = s->x;
+            s->points[front].y = s->y;
+            front++;
         }
 
         if (ret = ff_inlink_make_frame_writable(link, &frame)) {
@@ -320,34 +319,34 @@
             return ret;
         }
 
-        while (s->front > s->back) {
+        while (front > 0) {
             int x, y;
 
-            s->front--;
-            x = s->points[s->front].x;
-            y = s->points[s->front].y;
+            front--;
+            x = s->points[front].x;
+            y = s->points[front].y;
 
             if (s->is_same(frame, x, y, s0, s1, s2, s3)) {
                 s->set_pixel(frame, x, y, d0, d1, d2, d3);
 
                 if (is_inside(x + 1, y, w, h)) {
-                    s->points[s->front]  .x = x + 1;
-                    s->points[s->front++].y = y;
+                    s->points[front]  .x = x + 1;
+                    s->points[front++].y = y;
                 }
 
                 if (is_inside(x - 1, y, w, h)) {
-                    s->points[s->front]  .x = x - 1;
-                    s->points[s->front++].y = y;
+                    s->points[front]  .x = x - 1;
+                    s->points[front++].y = y;
                 }
 
                 if (is_inside(x, y + 1, w, h)) {
-                    s->points[s->front]  .x = x;
-                    s->points[s->front++].y = y + 1;
+                    s->points[front]  .x = x;
+                    s->points[front++].y = y + 1;
                 }
 
                 if (is_inside(x, y - 1, w, h)) {
-                    s->points[s->front]  .x = x;
-                    s->points[s->front++].y = y - 1;
+                    s->points[front]  .x = x;
+                    s->points[front++].y = y - 1;
                 }
             }
         }

++++++ ffmpeg-7-CVE-2026-65706.patch ++++++
>From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sat, 11 Jul 2026 16:46:39 +0200
Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest
 plane

Fixes: out of array access
Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
Fixes: VRAXYvKtmKa8
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_swaprect.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c
index 5d93f51c30..fe007ee5e7 100644
--- a/libavfilter/vf_swaprect.c
+++ b/libavfilter/vf_swaprect.c
@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink)
 {
     AVFilterContext *ctx = inlink->dst;
     SwapRectContext *s = ctx->priv;
+    int size = 0;
 
     if (!s->w  || !s->h  ||
         !s->x1 || !s->y1 ||
@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink)
     av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc);
     s->nb_planes = av_pix_fmt_count_planes(inlink->format);
 
-    s->temp = av_malloc_array(inlink->w, s->pixsteps[0]);
+    for (int p = 0; p < s->nb_planes; p++) {
+        int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0;
+        int width = AV_CEIL_RSHIFT(inlink->w, shift);
+
+        if (width > INT_MAX / s->pixsteps[p])
+            return AVERROR(EINVAL);
+        size = FFMAX(size, width * s->pixsteps[p]);
+    }
+
+    s->temp = av_malloc(size);
     if (!s->temp)
         return AVERROR(ENOMEM);
 
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-66036-shim01.patch ++++++
>From e3d0c719fddd259709c8e275942ab56af3afc35d Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 13:05:07 +0200
Subject: [PATCH] avfilter/vf_hqdn3d: reject unsupported frame parameter
 changes

Fixes: out of array access
Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py
Fixes: wWDsy2oDvMuR
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++---------
 libavfilter/vf_hqdn3d.h |  2 ++
 2 files changed, 27 insertions(+), 9 deletions(-)

diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c
index d880c2bdda..70a2ec4628 100644
--- a/libavfilter/vf_hqdn3d.c
+++ b/libavfilter/vf_hqdn3d.c
@@ -163,12 +163,8 @@ static int denoise_depth(HQDN3DContext *s,
             case 14: ret = denoise_depth(__VA_ARGS__, 14); break;             \
             case 16: ret = denoise_depth(__VA_ARGS__, 16); break;             \
         }                                                                     \
-        if (ret < 0) {                                                        \
-            av_frame_free(&out);                                              \
-            if (!direct)                                                      \
-                av_frame_free(&in);                                           \
+        if (ret < 0)                                                          \
             return ret;                                                       \
-        }                                                                     \
     } while (0)
 
 static void precalc_coefs(double dist25, int depth, int16_t *ct)
@@ -281,12 +277,15 @@ static int config_input(AVFilterLink *inlink)
     ff_hqdn3d_init_x86(s);
 #endif
 
+    s->format = inlink->format;
+    s->width  = inlink->w;
+    s->height = inlink->h;
+
     return 0;
 }
 
 typedef struct ThreadData {
     AVFrame *in, *out;
-    int direct;
 } ThreadData;
 
 static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs)
@@ -295,7 +294,6 @@ static int do_denoise(AVFilterContext *ctx, void *data, int 
job_nr, int n_jobs)
     const ThreadData *td = data;
     AVFrame *out = td->out;
     AVFrame *in = td->in;
-    int direct = td->direct;
 
     denoise(s, in->data[job_nr], out->data[job_nr],
                 s->line[job_nr], &s->frame_prev[job_nr],
@@ -312,10 +310,21 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in)
 {
     AVFilterContext *ctx  = inlink->dst;
     AVFilterLink *outlink = ctx->outputs[0];
+    HQDN3DContext *s = ctx->priv;
 
     AVFrame *out;
     int direct = av_frame_is_writable(in) && !ctx->is_disabled;
     ThreadData td;
+    int ret[3];
+
+    if (in->format != s->format ||
+        in->width  != s->width  ||
+        in->height != s->height) {
+        av_log(ctx, AV_LOG_ERROR,
+               "Frame size or format changed without filter graph 
reinitialization\n");
+        av_frame_free(&in);
+        return AVERROR(EINVAL);
+    }
 
     if (direct) {
         out = in;
@@ -331,9 +340,16 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in)
 
     td.in = in;
     td.out = out;
-    td.direct = direct;
     /* one thread per plane */
-    ff_filter_execute(ctx, do_denoise, &td, NULL, 3);
+    ff_filter_execute(ctx, do_denoise, &td, ret, 3);
+    for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) {
+        if (ret[i] < 0) {
+            av_frame_free(&out);
+            if (!direct)
+                av_frame_free(&in);
+            return ret[i];
+        }
+    }
 
     if (ctx->is_disabled) {
         av_frame_free(&out);
diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h
index 3279bbcc77..3467f27145 100644
--- a/libavfilter/vf_hqdn3d.h
+++ b/libavfilter/vf_hqdn3d.h
@@ -36,6 +36,8 @@ typedef struct HQDN3DContext {
     double strength[4];
     int hsub, vsub;
     int depth;
+    int width, height;
+    enum AVPixelFormat format;
     void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, 
uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal);
 } HQDN3DContext;
 
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-66036-shim02.patch ++++++
>From 4f623b4c59c3c838f588e9def7b59dcc26dee7b9 Mon Sep 17 00:00:00 2001
From: Niklas Haas <[email protected]>
Date: Fri, 16 May 2025 13:05:21 +0200
Subject: [PATCH] avfilter/vf_libplacebo: implement rotation option

Flipping can already be accomplished by setting the crop_w/h expressions to
their negative values, so together these options can implement any of the
common frame orientations.
---
 doc/filters.texi            | 10 ++++++++++
 libavfilter/avfilter.c      |  3 ++-
 libavfilter/vf_libplacebo.c | 23 +++++++++++++++++++++++
 3 files changed, 35 insertions(+), 1 deletion(-)

diff a/doc/filters.texi b/doc/filters.texi
--- a/doc/filters.texi
+++ b/doc/filters.texi
@@ -16419,6 +16419,16 @@ and @code{(oh-ph)/2}.
 Set the output placement width/height expressions, default values are @code{ow}
 and @code{oh}.
 
+@item rotate
+Rotate the input frame clockwise by the specified angle.
+
+@table @samp
+@item 0, 360
+@item 90
+@item 180
+@item 270
+@end table
+
 @item fps
 Set the output frame rate. This can be rational, e.g. @code{60000/1001}. If
 set to the special string @code{none} (the default), input timestamps will

diff a/libavfilter/avfilter.c b/libavfilter/avfilter.c
--- a/libavfilter/avfilter.c
+++ b/libavfilter/avfilter.c
@@ -1032,7 +1032,8 @@ int ff_filter_frame(AVFilterLink *link,
             strcmp(link->dst->filter->name, "format") &&
             strcmp(link->dst->filter->name, "idet") &&
             strcmp(link->dst->filter->name, "null") &&
-            strcmp(link->dst->filter->name, "scale")) {
+            strcmp(link->dst->filter->name, "scale") &&
+            strcmp(link->dst->filter->name, "libplacebo")) {
             av_assert1(frame->format        == link->format);
             av_assert1(frame->width         == link->w);
             av_assert1(frame->height        == link->h);

diff a/libavfilter/vf_libplacebo.c b/libavfilter/vf_libplacebo.c
--- a/libavfilter/vf_libplacebo.c
+++ b/libavfilter/vf_libplacebo.c
@@ -192,6 +192,7 @@ typedef struct LibplaceboContext {
     int color_range;
     int color_primaries;
     int color_trc;
+    int rotation;
     AVDictionary *extra_opts;
 
     /* pl_render_params */
@@ -787,6 +788,13 @@ static void update_crops(AVFilterContext
         image->crop.y0 = av_expr_eval(s->crop_y_pexpr, s->var_values, NULL);
         image->crop.x1 = image->crop.x0 + s->var_values[VAR_CROP_W];
         image->crop.y1 = image->crop.y0 + s->var_values[VAR_CROP_H];
+        image->rotation = s->rotation;
+        if (s->rotation % PL_ROTATION_180 == PL_ROTATION_90) {
+            /* Libplacebo expects the input crop relative to the actual frame
+             * dimensions, so un-transpose them here */
+            FFSWAP(float, image->crop.x0, image->crop.y0);
+            FFSWAP(float, image->crop.x1, image->crop.y1);
+        }
 
         if (src == ref) {
             /* Only update the target crop once, for the 'reference' frame */
@@ -1175,6 +1183,14 @@ static int libplacebo_config_input(AVFil
     AVFilterContext *avctx = inlink->dst;
     LibplaceboContext *s   = avctx->priv;
 
+    if (s->rotation % PL_ROTATION_180 == PL_ROTATION_90) {
+        /* Swap width and height for 90 degree rotations to make the size and
+         * scaling calculations work out correctly */
+        FFSWAP(int, inlink->w, inlink->h);
+        if (inlink->sample_aspect_ratio.num)
+            inlink->sample_aspect_ratio = 
av_inv_q(inlink->sample_aspect_ratio);
+    }
+
     if (inlink->format == AV_PIX_FMT_VULKAN)
         return ff_vk_filter_config_input(inlink);
 
@@ -1356,6 +1372,13 @@ static const AVOption libplacebo_options
     {"smpte2084",                      NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=AVCOL_TRC_SMPTE2084},    INT_MIN, INT_MAX, STATIC, .unit = "color_trc"},
     {"arib-std-b67",                   NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=AVCOL_TRC_ARIB_STD_B67}, INT_MIN, INT_MAX, STATIC, .unit = "color_trc"},
 
+    {"rotate", "rotate the input clockwise", OFFSET(rotation), 
AV_OPT_TYPE_INT, {.i64=PL_ROTATION_0}, PL_ROTATION_0, PL_ROTATION_360, DYNAMIC, 
.unit = "rotation"},
+    {"0",                              NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=PL_ROTATION_0},   .flags = STATIC, .unit = "rotation"},
+    {"90",                             NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=PL_ROTATION_90},  .flags = STATIC, .unit = "rotation"},
+    {"180",                            NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=PL_ROTATION_180}, .flags = STATIC, .unit = "rotation"},
+    {"270",                            NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=PL_ROTATION_270}, .flags = STATIC, .unit = "rotation"},
+    {"360",                            NULL,  0, AV_OPT_TYPE_CONST, 
{.i64=PL_ROTATION_360}, .flags = STATIC, .unit = "rotation"},
+
     { "upscaler", "Upscaler function", OFFSET(upscaler), AV_OPT_TYPE_STRING, 
{.str = "spline36"}, .flags = DYNAMIC },
     { "downscaler", "Downscaler function", OFFSET(downscaler), 
AV_OPT_TYPE_STRING, {.str = "mitchell"}, .flags = DYNAMIC },
     { "frame_mixer", "Frame mixing function", OFFSET(frame_mixer), 
AV_OPT_TYPE_STRING, {.str = "none"}, .flags = DYNAMIC },

++++++ ffmpeg-7-CVE-2026-66036.patch ++++++
>From 62294b6a8ad2370e1435bb9985ebe6b53be14c2b Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 13:05:33 +0200
Subject: [PATCH] avfilter/vf_hqdn3d: support dynamic frame sizes

(cherry picked from commit 5d7112c60e6f0f0742ce47d448e6da0718a70f4c)
---
 libavfilter/avfilter.c  |  3 ++-
 libavfilter/vf_hqdn3d.c | 21 ++++++++++++++-------
 2 files changed, 16 insertions(+), 8 deletions(-)

diff a/libavfilter/avfilter.c b/libavfilter/avfilter.c
--- a/libavfilter/avfilter.c
+++ b/libavfilter/avfilter.c
@@ -1033,7 +1033,8 @@
             strcmp(link->dst->filter->name, "idet") &&
             strcmp(link->dst->filter->name, "null") &&
             strcmp(link->dst->filter->name, "scale") &&
-            strcmp(link->dst->filter->name, "libplacebo")) {
+            strcmp(link->dst->filter->name, "libplacebo") &&
+            strcmp(link->dst->filter->name, "hqdn3d")) {
             av_assert1(frame->format        == link->format);
             av_assert1(frame->width         == link->w);
             av_assert1(frame->height        == link->h);

diff a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c
--- a/libavfilter/vf_hqdn3d.c
+++ b/libavfilter/vf_hqdn3d.c
@@ -315,21 +315,28 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in)
     AVFrame *out;
     int direct = av_frame_is_writable(in) && !ctx->is_disabled;
     ThreadData td;
-    int ret[3];
+    int err, ret[3];
 
-    if (in->format != s->format ||
-        in->width  != s->width  ||
-        in->height != s->height) {
-        av_log(ctx, AV_LOG_ERROR,
-               "Frame size or format changed without filter graph 
reinitialization\n");
+    if (in->format != s->format) {
         av_frame_free(&in);
         return AVERROR(EINVAL);
     }
 
+    if (in->width != s->width || in->height != s->height) {
+        inlink->w = in->width;
+        inlink->h = in->height;
+        if ((err = config_input(inlink)) < 0) {
+            av_frame_free(&in);
+            return err;
+        }
+        outlink->w = in->width;
+        outlink->h = in->height;
+    }
+
     if (direct) {
         out = in;
     } else {
-        out = ff_get_video_buffer(outlink, outlink->w, outlink->h);
+        out = ff_get_video_buffer(outlink, in->width, in->height);
         if (!out) {
             av_frame_free(&in);
             return AVERROR(ENOMEM);
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-66037.patch ++++++
>From f15e730cd225763bbae68614af777560aeb449dd Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 28 Jun 2026 22:05:28 +0200
Subject: [PATCH] avformat/iamf_parse: check count_label against the available
 bytes

Fixes: unbounded allocation / denial of service
Fixes: tP59h4cpaFyg
Fixes: 4ee05182b7 (avformat: Immersive Audio Model and Formats demuxer)
Found-by: Adrian Junge (vurlo)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 86708357d126af84c16f80d9c57335d1e8c845c5)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/iamf_parse.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/libavformat/iamf_parse.c b/libavformat/iamf_parse.c
index d74a8677d6..4c2df2c9e6 100644
--- a/libavformat/iamf_parse.c
+++ b/libavformat/iamf_parse.c
@@ -1009,6 +1009,11 @@ static int mix_presentation_obu(void *s, IAMFContext *c, 
AVIOContext *pb, int le
     mix_presentation->cmix = mix;
 
     mix_presentation->count_label = ffio_read_leb(pbc);
+    if (mix_presentation->count_label > len - avio_tell(pbc)) {
+        mix_presentation->count_label = 0;
+        ret = AVERROR_INVALIDDATA;
+        goto fail;
+    }
     mix_presentation->language_label = av_calloc(mix_presentation->count_label,
                                                  
sizeof(*mix_presentation->language_label));
     if (!mix_presentation->language_label) {
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-66038.patch ++++++
>From e7cbfd1c507b57a806a5825b87d609963e862c8c Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 28 Jun 2026 19:04:07 +0200
Subject: [PATCH] avcodec/lcldec: zero the not-decoded tail to avoid heap
 disclosure

Fixes: use of uninitialized memory
Fixes: CsNDKB1K1U0C
Fixes: e2c3aa8e2b (avcodec/lcldec: More space for rgb24)
Found-by: Adrian Junge (vurlo)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/lcldec.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/libavcodec/lcldec.c b/libavcodec/lcldec.c
index 29b1d85be3..5023243017 100644
--- a/libavcodec/lcldec.c
+++ b/libavcodec/lcldec.c
@@ -120,6 +120,9 @@ static unsigned int mszh_decomp(const unsigned char * 
srcptr, int srclen, unsign
         }
     }
 
+    if (destptr < destptr_end)
+        memset(destptr, 0, destptr_end - destptr);
+
     return destptr - destptr_bak;
 }
 
@@ -153,8 +156,11 @@ static int zlib_decomp(AVCodecContext *avctx, const 
uint8_t *src, int src_len, i
     if (expected != (unsigned int)zstream->total_out) {
         av_log(avctx, AV_LOG_ERROR, "Decoded size differs (%d != %lu)\n",
                expected, zstream->total_out);
-        if (expected > (unsigned int)zstream->total_out)
+        if (expected > (unsigned int)zstream->total_out) {
+            memset(c->decomp_buf + offset + zstream->total_out, 0,
+                   c->decomp_size - offset - zstream->total_out);
             return (unsigned int)zstream->total_out;
+        }
         return AVERROR_UNKNOWN;
     }
     return zstream->total_out;
-- 
2.54.0


++++++ ffmpeg-7-CVE-2026-66039.patch ++++++
>From aafb5c655edc76a753275c383ebb139feb032718 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Mon, 29 Jun 2026 01:16:44 +0200
Subject: [PATCH] avcodec/mace: reject sample counts that overflow int

Fixes: heap buffer overflow
Fixes: FmXBI2dbgvgD
Fixes: 0eea212943544d40f99b05571aa7159d78667154 (Add avcodec_decode_audio4().)
Found-by: Adrian Junge (vurlo)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/mace.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/libavcodec/mace.c b/libavcodec/mace.c
index 299e5f5cfe..87e802684a 100644
--- a/libavcodec/mace.c
+++ b/libavcodec/mace.c
@@ -252,7 +252,10 @@ static int mace_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
     }
 
     /* get output buffer */
-    frame->nb_samples = 3 * (buf_size << (1 - is_mace3)) / channels;
+    int64_t nb_samples = 3 * ((int64_t)buf_size << (1 - is_mace3)) / channels;
+    if (nb_samples > INT_MAX)
+        return AVERROR_INVALIDDATA;
+    frame->nb_samples = nb_samples;
     if ((ret = ff_get_buffer(avctx, frame, 0)) < 0)
         return ret;
     samples = (int16_t **)frame->extended_data;
-- 
2.54.0


++++++ ffmpeg-7-CVE-2026-66041.patch ++++++
>From 4da9812e25894fb51d62a8875cfa8eb39b5e20f5 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 28 Jun 2026 15:33:38 +0200
Subject: [PATCH] avfilter/vf_quirc: resize the quirc buffers when the input
 size changes

Fixes: out of array access
Fixes: JbvzNObhorBp
Fixes: 030e140145 (lavfi: add quirc filter)
Found-by: Adrian Junge (vurlo)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_quirc.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/libavfilter/vf_quirc.c b/libavfilter/vf_quirc.c
index 59dc84caa8..d2ba48e7bc 100644
--- a/libavfilter/vf_quirc.c
+++ b/libavfilter/vf_quirc.c
@@ -36,6 +36,7 @@ typedef struct QuircContext {
     const AVClass *class;
 
     struct quirc *quirc;
+    int width, height;
 } QuircContext;
 
 static av_cold int init(AVFilterContext *ctx)
@@ -67,6 +68,8 @@ static int config_input(AVFilterLink *inlink)
     if (err == -1) {
         return AVERROR(ENOMEM);
     }
+    quirc->width  = inlink->w;
+    quirc->height = inlink->h;
 
     return 0;
 }
@@ -80,6 +83,15 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *frame)
     int codes_count;
     uint8_t *image;
 
+    if (quirc->width != inlink->w || quirc->height != inlink->h) {
+        if (quirc_resize(quirc->quirc, inlink->w, inlink->h) < 0) {
+            av_frame_free(&frame);
+            return AVERROR(ENOMEM);
+        }
+        quirc->width  = inlink->w;
+        quirc->height = inlink->h;
+    }
+
     /* copy input image to quirc buffer */
     image = quirc_begin(quirc->quirc, NULL, NULL);
     av_image_copy_plane(image, inlink->w,
-- 
2.54.0


++++++ ffmpeg-7-CVE-2026-70628.patch ++++++
>From 02fc47e13f903768b75f7985a2706a6223ab4506 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:49:11 +0200
Subject: [PATCH] avcodec/dvbsub_parser: avoid signed overflow in the capacity
 check

Fixes: signed integer overflow
Fixes: out of array access
Fixes: poc.wtv
Fixes: fJeEU9JwKwsR
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 93f2a525ec6c7b467bae68322720d10188fc6e30)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/dvbsub_parser.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavcodec/dvbsub_parser.c b/libavcodec/dvbsub_parser.c
index 4527e4dd75..a93f39bfe0 100644
--- a/libavcodec/dvbsub_parser.c
+++ b/libavcodec/dvbsub_parser.c
@@ -104,7 +104,7 @@ static int dvbsub_parse(AVCodecParserContext *s,
         }
     }
 
-    if (buf_size - buf_pos + pc->packet_index > PARSE_BUF_SIZE)
+    if (buf_size - buf_pos > PARSE_BUF_SIZE - pc->packet_index)
         return buf_size;
 
 /* if not currently in a packet, pass data */
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-70629.patch ++++++
>From a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:03 +0200
Subject: [PATCH] avcodec/rscc: do not leave uninitilized data when the input
 is too short

Fixes: use of uninitialized memory
Fixes: rscc_short_deflate_heap_disclosure.avi
Fixes: plB80py3i3Bu
Found-by: Adrian Junge (vurlo)
(cherry picked from commit cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/rscc.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/libavcodec/rscc.c b/libavcodec/rscc.c
index 3715e1c6d4..5fde30ec35 100644
--- a/libavcodec/rscc.c
+++ b/libavcodec/rscc.c
@@ -311,6 +311,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
             ret = AVERROR_UNKNOWN;
             goto end;
         }
+        if (len < pixel_size) {
+            av_log(avctx, AV_LOG_WARNING, "Deflated %lu bytes, but %d are 
needed\n",
+                   len, pixel_size);
+            memset(ctx->inflated_buf + len, 0, pixel_size - len);
+            pixel_size = len;
+        }
         pixels = ctx->inflated_buf;
     }
 
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-70630.patch ++++++
>From c22667d0fd7916a33fd3e79685b7246fc48f1a62 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:41 +0200
Subject: [PATCH] avcodec/screenpresso: reject deflate output shorter than the
 frame

Fixes: use of uninitialized memory
Fixes: screenpresso_short_zlib_heap_disclosure.avi
Fixes: ksUBwBOjJodq
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 705890061467ad550ecc1dad5eea07f28ccfb43e)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/screenpresso.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c
index b27154991c..5864253d41 100644
--- a/libavcodec/screenpresso.c
+++ b/libavcodec/screenpresso.c
@@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
         return AVERROR_INVALIDDATA;
     }
 
+    /* Codec has aligned strides */
+    src_linesize = FFALIGN(avctx->width * component_size, 4);
+
     /* Inflate the frame after the 2 byte header */
     ret = uncompress(ctx->inflated_buf, &length,
                      avpkt->data + 2, avpkt->size - 2);
@@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext 
*avctx, AVFrame *frame,
         av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret);
         return AVERROR_UNKNOWN;
     }
+    if (length < src_linesize * avctx->height) {
+        av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n",
+               length, src_linesize * avctx->height);
+        return AVERROR_INVALIDDATA;
+    }
 
     ret = ff_reget_buffer(avctx, ctx->current, 0);
     if (ret < 0)
         return ret;
 
-    /* Codec has aligned strides */
-    src_linesize = FFALIGN(avctx->width * component_size, 4);
-
     /* When a keyframe is found, copy it (flipped) */
     if (keyframe)
         av_image_copy_plane(ctx->current->data[0] +
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-70631.patch ++++++
>From 3c287af3affe1286350faa69c02bcc5d49de18bb Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:41 +0200
Subject: [PATCH] avcodec/tiff: reject inflate output shorter than the strip

Fixes: use of uninitialized memory
Fixes: tiff_short_deflate_heap_disclosure.tiff
Fixes: 1cRIkpUVMQtn
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 2f234ea34c81288e3840fca632dd16481d8de39f)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/tiff.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c
index 8a179f0fd0..b8ce7b0b55 100644
--- a/libavcodec/tiff.c
+++ b/libavcodec/tiff.c
@@ -526,6 +526,7 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
     uint8_t *zbuf;
     unsigned long outlen;
     int ret, line;
+    int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : 
lines;
     outlen = width * lines;
     zbuf   = av_malloc(outlen);
     if (!zbuf)
@@ -545,6 +546,12 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
         av_free(zbuf);
         return AVERROR_UNKNOWN;
     }
+    if (outlen < (unsigned long)width * rows) {
+        av_log(s->avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %lu are 
needed\n",
+               outlen, (unsigned long)width * rows);
+        av_free(zbuf);
+        return AVERROR_INVALIDDATA;
+    }
     src = zbuf;
     for (line = 0; line < lines; line++) {
         if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) {
@@ -592,6 +599,7 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
 {
     uint64_t outlen = width * (uint64_t)lines;
     int ret, line;
+    int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : 
lines;
     uint8_t *buf = av_malloc(outlen);
     if (!buf)
         return AVERROR(ENOMEM);
@@ -610,6 +618,12 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
         av_free(buf);
         return AVERROR_UNKNOWN;
     }
+    if (outlen < (uint64_t)width * rows) {
+        av_log(s->avctx, AV_LOG_ERROR, "Uncompressed %"PRIu64" bytes, but 
%"PRIu64" are needed\n",
+               outlen, (uint64_t)width * rows);
+        av_free(buf);
+        return AVERROR_INVALIDDATA;
+    }
     src = buf;
     for (line = 0; line < lines; line++) {
         if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) {
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-70632.patch ++++++
>From 16b2049d4d5222db6cd7c031409058571c94f6a9 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:53:16 +0200
Subject: [PATCH] avcodec/cfhd: reject transform-2 output wider than the plane

Fixes: out of array access
Fixes: cfhd_transform2_output_width_oob.avi
Fixes: MimvoaEVpKow
Found-by: Adrian Junge (vurlo)
(cherry picked from commit db05df9d135fb56a4babb836d5e9f5c1d984e087)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/cfhd.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/libavcodec/cfhd.c b/libavcodec/cfhd.c
index 4d430e32ef..128362ac62 100644
--- a/libavcodec/cfhd.c
+++ b/libavcodec/cfhd.c
@@ -1224,7 +1224,7 @@ finish:
 
             if (lowpass_height > s->plane[plane].band[4][1].a_height || 
lowpass_width > s->plane[plane].band[4][1].a_width ||
                 !highpass_stride || s->plane[plane].band[4][1].width > 
s->plane[plane].band[4][1].a_width ||
-                lowpass_width < 3 || lowpass_height < 3) {
+                lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > 
s->plane[plane].width) {
                 av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n");
                 ret = AVERROR(EINVAL);
                 goto end;
@@ -1345,7 +1345,7 @@ finish:
 
             if (lowpass_height > s->plane[plane].band[4][1].a_height || 
lowpass_width > s->plane[plane].band[4][1].a_width ||
                 s->plane[plane].band[4][1].width > 
s->plane[plane].band[4][1].a_width ||
-                lowpass_width < 3 || lowpass_height < 3) {
+                lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > 
s->plane[plane].width) {
                 av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n");
                 ret = AVERROR(EINVAL);
                 goto end;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-75141.patch ++++++
>From acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:56 +0000
Subject: [PATCH] avformat/hevc: reject hvcC NAL arrays that overflow the
 16-bit count

numNalus is uint16_t; a crafted hvcC declaring >65535 NAL units of one
type wraps it to 0 and then writes nal[-1]. Reject before the count can
wrap. Reachable by remuxing a crafted file with -c copy.

Fixes: integer overflow
Fixes: out of array access
---
 libavformat/hevc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/libavformat/hevc.c b/libavformat/hevc.c
index c9ee11f36c..678a9e2206 100644
--- a/libavformat/hevc.c
+++ b/libavformat/hevc.c
@@ -844,6 +844,9 @@ static int hvcc_array_add_nal_unit(const uint8_t *nal_buf, 
uint32_t nal_size,
     int ret;
     uint16_t numNalus = array->numNalus;
 
+    if (numNalus >= UINT16_MAX)
+        return AVERROR_INVALIDDATA;
+
     ret = av_reallocp_array(&array->nal, numNalus + 1, sizeof(*array->nal));
     if (ret < 0)
         return ret;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-75142.patch ++++++
>From 9d786e4b5e9b8482651928574de33772aeee7be1 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/mpegenc: reject stream counts that overflow the
 system header

put_system_header() writes 12 + 3*N bytes after the pack header into a
fixed 128-byte stack buffer, but is handed a PutBitContext sized past the
real buffer, so its own bounds check never fires; ~35+ streams overflow the
stack. Reject at mux init when the system header would not fit.

Fixes: out of array access
Fixes: many.mkv
---
 libavformat/mpegenc.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/libavformat/mpegenc.c b/libavformat/mpegenc.c
index 128dfe2885..cea91d80da 100644
--- a/libavformat/mpegenc.c
+++ b/libavformat/mpegenc.c
@@ -473,6 +473,16 @@ static av_cold int mpeg_mux_init(AVFormatContext *ctx)
         if (!stream->fifo)
             return AVERROR(ENOMEM);
     }
+
+    /* The system header is emitted, right after the pack header (which is at
+     * most 14 bytes), into the fixed 128-byte buffer used by flush_packet().
+     * Reject configurations whose system header would not fit. */
+    if (get_system_header_size(ctx) > 128 - 14) {
+        av_log(ctx, AV_LOG_ERROR,
+               "Too many streams to fit the MPEG program stream system 
header\n");
+        return AVERROR(EINVAL);
+    }
+
     bitrate       = 0;
     audio_bitrate = 0;
     video_bitrate = 0;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-75143.patch ++++++
>From 1c10bcc2e17255dacb717a25ab3db142ce390602 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/librist: honor the caller buffer size in
 librist_read

librist_read() ignored its size argument and copied the full payload_len,
overflowing a smaller destination (e.g. via the async: wrapper). Clamp the
copy to the caller-provided buffer size.

Fixes: out of array access
---
 libavformat/librist.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/librist.c b/libavformat/librist.c
index 9669d5b5df..3c4b5e3e5b 100644
--- a/libavformat/librist.c
+++ b/libavformat/librist.c
@@ -226,7 +226,7 @@ static int librist_read(URLContext *h, uint8_t *buf, int 
size)
         }
     }
 
-    size = data_block->payload_len;
+    size = FFMIN(data_block->payload_len, size);
     memcpy(buf, data_block->payload, size);
 out_free:
     rist_receiver_data_block_free2(&data_block);
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-75144.patch ++++++
>From 1cdeb3c4e7f1f8566d846b9b451e01c376398818 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/rtpenc_vc2hq: reject data units larger than the RTP
 payload buffer

send_packet() copied an input-derived unit/fragment size into the fixed
rtp_ctx->buf with no bound, overflowing it for a crafted Dirac unit even at
the default packet size. Reject units that do not fit in max_payload_size.

Fixes: out of array access
---
 libavformat/rtpenc_vc2hq.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index cf548191d2..3b7147dfe2 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -33,16 +33,23 @@
 #define DIRAC_PIC_NR_SIZE                    4
 #define DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT      0xEC
 
-static void send_packet(AVFormatContext *ctx, uint8_t parse_code, int 
info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m)
+static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int 
info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m)
 {
     RTPMuxContext *rtp_ctx = ctx->priv_data;
 
+    if (size < 0 ||
+        size > rtp_ctx->max_payload_size - RTP_VC2HQ_PL_HEADER_SIZE - 
info_hdr_size) {
+        av_log(ctx, AV_LOG_ERROR, "VC-2 data unit too large for RTP payload 
buffer\n");
+        return AVERROR_INVALIDDATA;
+    }
+
     AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */
     AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: 
interlaced, second field */
     AV_WB8 (&rtp_ctx->buf[3], parse_code);
     if (size > 0)
         memcpy(&rtp_ctx->buf[4 + info_hdr_size], buf, size);
     ff_rtp_send_data(ctx, rtp_ctx->buf, RTP_VC2HQ_PL_HEADER_SIZE + 
info_hdr_size + size, rtp_m);
+    return 0;
 }
 
 static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, 
int interlaced)
@@ -85,7 +92,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t 
*buf, int size, int
     AV_WB16(&info_hdr[ 6], size_scaler);
     AV_WB16(&info_hdr[ 8], frag_len);
     AV_WB16(&info_hdr[10], 0 /* nr. of slices */);
-    send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, 
interlaced, second_field, 0);
+    if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, 
interlaced, second_field, 0) < 0)
+        return AVERROR_INVALIDDATA;
     buf += frag_len;
     size -= frag_len;
 
@@ -97,7 +105,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t 
*buf, int size, int
         AV_WB16(&info_hdr[14], 0 /* slice y */);
 
         size -= frag_len;
-        send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, 
interlaced, second_field, size > 0 ? 0 : 1);
+        if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, 
frag_len, interlaced, second_field, size > 0 ? 0 : 1) < 0)
+            return AVERROR_INVALIDDATA;
         buf += frag_len;
     }
     return 0;
-- 
2.49.0


++++++ ffmpeg-7-CVE-2026-75146.patch ++++++
>From 65b0dab903e5975e036b30ecc58f5935d4f151e0 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/dashdec: reject a negative fragment index

A live manifest whose startNumber decreases across a refresh drives
cur_seq_no negative in move_segments(); get_current_fragment() only checked
the upper bound before indexing fragments[]. Add a lower-bound check and
clamp the negative delta at its source.

Fixes: out of array read
---
 libavformat/dashdec.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff a/libavformat/dashdec.c b/libavformat/dashdec.c
--- a/libavformat/dashdec.c
+++ b/libavformat/dashdec.c
@@ -1488,8 +1488,11 @@ static void move_segments(struct represe
         free_fragment_list(rep_dest);
         if (rep_src->start_number > (rep_dest->start_number + 
rep_dest->n_fragments))
             rep_dest->cur_seq_no = 0;
-        else
+        else {
             rep_dest->cur_seq_no += rep_src->start_number - 
rep_dest->start_number;
+            if (rep_dest->cur_seq_no < 0)
+                rep_dest->cur_seq_no = 0;
+        }
         rep_dest->fragments    = rep_src->fragments;
         rep_dest->n_fragments  = rep_src->n_fragments;
         rep_dest->parent  = rep_src->parent;
@@ -1608,7 +1611,7 @@ static struct fragment *get_current_frag
     DASHContext *c = pls->parent->priv_data;
 
     while (( !ff_check_interrupt(c->interrupt_callback)&& pls->n_fragments > 
0)) {
-        if (pls->cur_seq_no < pls->n_fragments) {
+        if (pls->cur_seq_no >= 0 && pls->cur_seq_no < pls->n_fragments) {
             seg_ptr = pls->fragments[pls->cur_seq_no];
             seg = av_mallocz(sizeof(struct fragment));
             if (!seg) {

Reply via email to