Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package ffmpeg-8 for openSUSE:Factory 
checked in at 2026-09-04 12:35:50
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/ffmpeg-8 (Old)
 and      /work/SRC/openSUSE:Factory/.ffmpeg-8.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "ffmpeg-8"

Fri Sep  4 12:35:50 2026 rev:15 rq:1375173 version:8.1.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/ffmpeg-8/ffmpeg-8.changes        2026-07-23 
23:09:04.253607907 +0200
+++ /work/SRC/openSUSE:Factory/.ffmpeg-8.new.1265/ffmpeg-8.changes      
2026-09-04 12:35:53.240054337 +0200
@@ -1,0 +2,188 @@
+Mon Aug 28 05:22:38 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75147.patch:
+  Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU
+  size in the keyframe search loop.
+  (CVE-2026-75147, bsc#1276413)
+
+-------------------------------------------------------------------
+Mon Aug 28 04:47:54 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75146.patch:
+  Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative
+  fragment index.
+  (CVE-2026-75146, bsc#1276412)
+
+-------------------------------------------------------------------
+Mon Aug 28 04:02:17 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75145.patch:
+  Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow
+  the OBU size to (long).
+  (CVE-2026-75145, bsc#1276411)
+
+-------------------------------------------------------------------
+Mon Aug 28 03:34:50 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75144.patch:
+  Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data
+  units larger than the RTP payload buffer.
+  (CVE-2026-75144, bsc#1276410)
+
+-------------------------------------------------------------------
+Mon Aug 28 03:17:21 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75143.patch:
+  Backport 1c10bcc2 from upstream, avformat/librist: honor the caller
+  buffer size in librist_read.
+  (CVE-2026-75143, bsc#1276409)
+
+-------------------------------------------------------------------
+Mon Aug 28 02:58:12 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75142.patch:
+  Backport 9d786e4b from upstream, avformat/mpegenc: reject stream
+  counts that overflow the system header.
+  (CVE-2026-75142, bsc#1276408)
+
+-------------------------------------------------------------------
+Mon Aug 28 02:44:56 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-75141.patch:
+  Backport acf5d7cd from upstream, avformat/hevc: reject hvcC
+  NAL arrays that overflow the 16-bit count.
+  (CVE-2026-75141, bsc#1276407)
+
+-------------------------------------------------------------------
+Wed Aug 14 09:44:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-70632.patch:
+  Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2
+  output wider than the plane.
+  (CVE-2026-70632, bsc#1274289)
+
+-------------------------------------------------------------------
+Wed Aug 14 08:27:41 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-70631.patch:
+  Backport 3c287af3 from upstream, avcodec/tiff: reject inflate
+  output shorter than the strip.
+  (CVE-2026-70631, bsc#1274287)
+
+-------------------------------------------------------------------
+Wed Aug 14 07:58:24 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-70630.patch:
+  Backport c22667d0 from upstream, avcodec/screenpresso: reject
+  deflate output shorter than the frame.
+  (CVE-2026-70630, bsc#1274282)
+
+-------------------------------------------------------------------
+Wed Aug 14 07:22:18 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-70629.patch:
+  Backport a5fe21a1 from upstream, avcodec/rscc: do not leave
+  uninitilized data when the input is too short.
+  (CVE-2026-70629, bsc#1274270)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:52:11 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-70628.patch:
+  Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid
+  signed overflow in the capacity check.
+  (CVE-2026-70628, bsc#1274268)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:41:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-66037.patch:
+  Backport f15e730c from upstream, avformat/iamf_parse: check
+  count_label against the available bytes.
+  (CVE-2026-66037, bsc#1272764)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:28:33 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-66036.patch:
+  Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support
+  dynamic frame sizes.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 05:51:42 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-66036-shim01.patch
+  Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject
+  unsupported frame parameter changes. This patch is for facilitate 
+  ffmpeg-CVE-2026-66036.patch.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 05:31:22 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-65706.patch:
+  Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the
+  temp row buffer for the widest plane.
+  (CVE-2026-65706, bsc#1272762)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:56:09 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-65705.patch:
+  Backport 30a52276 from upstream, avfilter/vf_floodfill: remove
+  unneeded variables.
+  (CVE-2026-65705, bsc#1272761)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:31:19 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-65704.patch:
+  Backport 52f7983f from upstream, avformat/ty: don't let the Series2
+  AC3 trim underflow the packet size.
+  (CVE-2026-65704, bsc#1272760)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:02:11 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-65703.patch:
+  Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference
+  frame before reallocating on size change.
+  (CVE-2026-65703, bsc#1272759)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:46:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-64834.patch:
+  Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF
+  objects smaller than their header.
+  (CVE-2026-64834, bsc#1272757)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:33:14 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-64833.patch:
+  Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS
+  core_size against the packet size in the HD path.
+  (CVE-2026-64833, bsc#1272755)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:28:13 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-8-CVE-2026-58049.patch:
+  Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit
+  DLTA accesses stay within the row.
+  (CVE-2026-58049, bsc#1269550)
+ 
+-------------------------------------------------------------------
+Tue Aug 11 10:43:34 UTC 2026 - Jan Engelhardt <[email protected]>
+
+- Rename the ffmpeg BRPM back to ffmpeg-8 to make room for ffmpeg-9
+  to fill the role. [boo#1271606]
+
+-------------------------------------------------------------------
+Tue Jul 21 13:58:03 UTC 2026 - Jan Engelhardt <[email protected]>
+
+- Rename the ffmpeg-8 BRPM to ffmpeg. [boo#1271606]
+
+-------------------------------------------------------------------

New:
----
  ffmpeg-8-CVE-2026-58049.patch
  ffmpeg-8-CVE-2026-64833.patch
  ffmpeg-8-CVE-2026-64834.patch
  ffmpeg-8-CVE-2026-65703.patch
  ffmpeg-8-CVE-2026-65704.patch
  ffmpeg-8-CVE-2026-65705.patch
  ffmpeg-8-CVE-2026-65706.patch
  ffmpeg-8-CVE-2026-66036-shim01.patch
  ffmpeg-8-CVE-2026-66036.patch
  ffmpeg-8-CVE-2026-66037.patch
  ffmpeg-8-CVE-2026-70628.patch
  ffmpeg-8-CVE-2026-70629.patch
  ffmpeg-8-CVE-2026-70630.patch
  ffmpeg-8-CVE-2026-70631.patch
  ffmpeg-8-CVE-2026-70632.patch
  ffmpeg-8-CVE-2026-75141.patch
  ffmpeg-8-CVE-2026-75142.patch
  ffmpeg-8-CVE-2026-75143.patch
  ffmpeg-8-CVE-2026-75144.patch
  ffmpeg-8-CVE-2026-75145.patch
  ffmpeg-8-CVE-2026-75146.patch
  ffmpeg-8-CVE-2026-75147.patch

----------(New B)----------
  New:
- Add ffmpeg-8-CVE-2026-58049.patch:
  Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit
  New:
- Add ffmpeg-8-CVE-2026-64833.patch:
  Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS
  New:
- Add ffmpeg-8-CVE-2026-64834.patch:
  Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF
  New:
- Add ffmpeg-8-CVE-2026-65703.patch:
  Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference
  New:
- Add ffmpeg-8-CVE-2026-65704.patch:
  Backport 52f7983f from upstream, avformat/ty: don't let the Series2
  New:
- Add ffmpeg-8-CVE-2026-65705.patch:
  Backport 30a52276 from upstream, avfilter/vf_floodfill: remove
  New:
- Add ffmpeg-8-CVE-2026-65706.patch:
  Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the
  New:
- Add ffmpeg-8-CVE-2026-66036-shim01.patch
  Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject
  New:
- Add ffmpeg-8-CVE-2026-66036.patch:
  Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support
  New:
- Add ffmpeg-8-CVE-2026-66037.patch:
  Backport f15e730c from upstream, avformat/iamf_parse: check
  New:
- Add ffmpeg-8-CVE-2026-70628.patch:
  Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid
  New:
- Add ffmpeg-8-CVE-2026-70629.patch:
  Backport a5fe21a1 from upstream, avcodec/rscc: do not leave
  New:
- Add ffmpeg-8-CVE-2026-70630.patch:
  Backport c22667d0 from upstream, avcodec/screenpresso: reject
  New:
- Add ffmpeg-8-CVE-2026-70631.patch:
  Backport 3c287af3 from upstream, avcodec/tiff: reject inflate
  New:
- Add ffmpeg-8-CVE-2026-70632.patch:
  Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2
  New:
- Add ffmpeg-8-CVE-2026-75141.patch:
  Backport acf5d7cd from upstream, avformat/hevc: reject hvcC
  New:
- Add ffmpeg-8-CVE-2026-75142.patch:
  Backport 9d786e4b from upstream, avformat/mpegenc: reject stream
  New:
- Add ffmpeg-8-CVE-2026-75143.patch:
  Backport 1c10bcc2 from upstream, avformat/librist: honor the caller
  New:
- Add ffmpeg-8-CVE-2026-75144.patch:
  Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data
  New:
- Add ffmpeg-8-CVE-2026-75145.patch:
  Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow
  New:
- Add ffmpeg-8-CVE-2026-75146.patch:
  Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative
  New:
- Add ffmpeg-8-CVE-2026-75147.patch:
  Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ ffmpeg-8.spec ++++++
--- /var/tmp/diff_new_pack.CWZjOR/_old  2026-09-04 12:35:55.068118520 +0200
+++ /var/tmp/diff_new_pack.CWZjOR/_new  2026-09-04 12:35:55.071118625 +0200
@@ -121,6 +121,28 @@
 Patch5:         work-around-abi-break.patch
 Patch10:        ffmpeg-chromium.patch
 Patch15:        
11013-avcodec-decode-clean-up-if-get_hw_frames_parameters-.patch
+Patch16:        ffmpeg-8-CVE-2026-58049.patch
+Patch17:        ffmpeg-8-CVE-2026-64833.patch
+Patch18:        ffmpeg-8-CVE-2026-64834.patch
+Patch19:        ffmpeg-8-CVE-2026-65703.patch
+Patch20:        ffmpeg-8-CVE-2026-65704.patch
+Patch21:        ffmpeg-8-CVE-2026-65705.patch
+Patch22:        ffmpeg-8-CVE-2026-65706.patch
+Patch23:        ffmpeg-8-CVE-2026-66036-shim01.patch
+Patch24:        ffmpeg-8-CVE-2026-66036.patch
+Patch25:        ffmpeg-8-CVE-2026-66037.patch
+Patch26:        ffmpeg-8-CVE-2026-70628.patch
+Patch27:        ffmpeg-8-CVE-2026-70629.patch
+Patch28:        ffmpeg-8-CVE-2026-70630.patch
+Patch29:        ffmpeg-8-CVE-2026-70631.patch
+Patch30:        ffmpeg-8-CVE-2026-70632.patch
+Patch31:        ffmpeg-8-CVE-2026-75141.patch
+Patch32:        ffmpeg-8-CVE-2026-75142.patch
+Patch33:        ffmpeg-8-CVE-2026-75143.patch
+Patch34:        ffmpeg-8-CVE-2026-75144.patch
+Patch35:        ffmpeg-8-CVE-2026-75145.patch
+Patch36:        ffmpeg-8-CVE-2026-75146.patch
+Patch37:        ffmpeg-8-CVE-2026-75147.patch
 BuildRequires:  c++_compiler
 BuildRequires:  ladspa-devel
 BuildRequires:  libgsm-devel

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.CWZjOR/_old  2026-09-04 12:35:55.167121996 +0200
+++ /var/tmp/diff_new_pack.CWZjOR/_new  2026-09-04 12:35:55.171122136 +0200
@@ -1,5 +1,5 @@
-mtime: 1784610487
-commit: 8b01d1fdbd7368419bcce37a7eac79f1f1085d35bf059ee052dbdb2cde1ad90e
+mtime: 1788270016
+commit: 404d61e94b16e44edc01e99a25f1b0f3318ce061cd57c23b075ad7188c2354b6
 url: https://src.opensuse.org/jengelh/ffmpeg
-revision: master
+revision: ff8
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-01 15:40:16.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ ffmpeg-8-CVE-2026-58049.patch ++++++
>From f8d7795dcca36a4dd412e89cbd83e3dfec1e0d81 Mon Sep 17 00:00:00 2001
From: Umar Pathan <[email protected]>
Date: Sun, 28 Jun 2026 23:02:52 +0200
Subject: [PATCH] avcodec/rasc: Check that 32-bit DLTA accesses stay within the
 row

Found-by: bikini (github.com/bikini/exploitarium)
Fixes: out of array access
Fixes: rowspill_128x1.avi / gen_rowspill_avi.py
Fixes: xGV79bIb7uAJ
(cherry picked from commit 11ff18a6c80187405fc492f9bb07ba9f2f663f76)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/rasc.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/libavcodec/rasc.c b/libavcodec/rasc.c
index 5f956a9b2c..d784a44063 100644
--- a/libavcodec/rasc.c
+++ b/libavcodec/rasc.c
@@ -320,6 +320,11 @@ static int decode_move(AVCodecContext *avctx,
     return 0;
 }
 
+static inline int dlta_room(unsigned cx, unsigned w, unsigned bpp, unsigned 
need)
+{
+    return cx + need <= w * bpp;
+}
+
 #define NEXT_LINE                        \
     if (cx >= w * s->bpp) {              \
         cx = 0;                          \
@@ -418,6 +423,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 4:
             fill = bytestream2_get_byte(&dc);
             while (len > 0 && cy > 0) {
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx++;
@@ -427,6 +434,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 7:
             fill = bytestream2_get_le32(&dc);
             while (len > 0 && cy > 0) {
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx += 4;
@@ -443,6 +452,8 @@ static int decode_dlta(AVCodecContext *avctx,
             while (len > 0 && cy > 0) {
                 unsigned v0, v1;
 
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 v0 = AV_RL32(b2 + cx);
                 v1 = AV_RL32(b1 + cx);
                 AV_WL32(b2 + cx, v1);
@@ -454,6 +465,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 13:
             while (len > 0 && cy > 0) {
                 fill = bytestream2_get_le32(&dc);
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx += 4;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-64833.patch ++++++
>From 385ac2fadcb4394ec4f65e5c4d3d24003e090f36 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Tue, 30 Jun 2026 00:11:50 +0200
Subject: [PATCH] avformat/spdifenc: bound DTS core_size against the packet
 size in the HD path

Fixes: out of array read
Fixes: yBSax492UIB9
Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 6f80e2765492700622596af720534cef33dd31b4)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/spdifenc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c
index ab3f73da0d..16eebda01c 100644
--- a/libavformat/spdifenc.c
+++ b/libavformat/spdifenc.c
@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket 
*pkt, int core_size,
              * (dtshd_fallback == 0) */
             ctx->dtshd_skip = 1;
     }
-    if (ctx->dtshd_skip && core_size) {
+    if (ctx->dtshd_skip && core_size && core_size <= pkt->size) {
         pkt_size = core_size;
         if (ctx->dtshd_fallback >= 0)
             --ctx->dtshd_skip;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-64834.patch ++++++
>From 3c441711a343ccf50196c70a3f0b554b52f8d9de Mon Sep 17 00:00:00 2001
From: Pavel Kohout <[email protected]>
Date: Tue, 30 Jun 2026 21:55:16 +0200
Subject: [PATCH] avformat/rtpdec_asf: reject ASF objects smaller than their
 header

Fixes: infinite loop
Fixes: MzWwJdpZF2Ls
Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet 
parsing.)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 11d5f475be95d22d5f0692220cc772b116abc632)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/rtpdec_asf.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c
index b3b346f3cc..f7fa69e27f 100644
--- a/libavformat/rtpdec_asf.c
+++ b/libavformat/rtpdec_asf.c
@@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len)
         uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid));
         int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2;
         if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) {
+            if (chunksize < sizeof(ff_asf_guid) + 8)
+                return -1;
             if (chunksize > end - p)
                 return -1;
             p += chunksize;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-65703.patch ++++++
>From 3b85fbe89025ea696988488358dfde41a09c53c5 Mon Sep 17 00:00:00 2001
From: Cloud-LHY <[email protected]>
Date: Fri, 10 Jul 2026 04:07:04 +0200
Subject: [PATCH] avcodec/tdsc: unref the reference frame before reallocating
 on size change

Fixes: out of array access
Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
Fixes: tdsc_resize_jpeg_oob.avi / 
tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
Fixes: p9xG4xGf9P7H
Fixes: HQL7a1WgTdHZ
Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS
Found-by: Adrian Junge (vurlo)
(cherry picked from commit fd3ee52fab34d98a95b787d0b5ff45685766200c)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/tdsc.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c
index ca9dd0f0a6..102b4ae966 100644
--- a/libavcodec/tdsc.c
+++ b/libavcodec/tdsc.c
@@ -485,11 +485,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int 
number_tiles)
             return ret;
         init_refframe = 1;
     }
-    ctx->refframe->width  = ctx->width  = w;
-    ctx->refframe->height = ctx->height = h;
+    ctx->width  = w;
+    ctx->height = h;
 
     /* Allocate the reference frame if not already done or on size change */
     if (init_refframe) {
+        av_frame_unref(ctx->refframe);
+        ctx->refframe->format = avctx->pix_fmt;
+        ctx->refframe->width  = w;
+        ctx->refframe->height = h;
         ret = av_frame_get_buffer(ctx->refframe, 0);
         if (ret < 0)
             return ret;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-65704.patch ++++++
>From 52f7983f15678c8a6065327760d7b6eb1c9c84ed Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Fri, 10 Jul 2026 04:07:35 +0200
Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the
 packet size

Fixes: negative-size-param
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)
(cherry picked from commit de771bd52774a52d45b0e2c82e56995a1ef40df7)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/ty.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/ty.c b/libavformat/ty.c
index 9be027fcca..842d97038c 100644
--- a/libavformat/ty.c
+++ b/libavformat/ty.c
@@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr 
*rec_hdr, AVPacket *pkt)
         if (ty->audio_type == TIVO_AUDIO_AC3 &&
                 ty->tivo_series == TIVO_SERIES2) {
             if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) {
-                pkt->size -= 2;
+                pkt->size -= FFMIN(pkt->size, 2);
                 ty->ac3_pkt_size = 0;
             } else {
                 ty->ac3_pkt_size += pkt->size;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-65705.patch ++++++
>From 30a52276f9dff60fe732d8bb8d463e587ff69c94 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 03:27:47 +0200
Subject: [PATCH] avfilter/vf_floodfill: remove unneeded variables

Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit f186c50cf53aec20e9a29059cb22ca3f2d59201c)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_floodfill.c | 35 ++++++++++++++++-------------------
 1 file changed, 16 insertions(+), 19 deletions(-)

diff a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
--- a/libavfilter/vf_floodfill.c
+++ b/libavfilter/vf_floodfill.c
@@ -39,7 +39,6 @@
     int d[4];
 
     int nb_planes;
-    int back, front;
     Points *points;
 
     int (*is_same)(const AVFrame *frame, int x, int y,
@@ -270,7 +269,6 @@
        }
     }
 
-    s->front = s->back = 0;
     s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points));
     if (!s->points)
         return AVERROR(ENOMEM);
@@ -293,6 +291,7 @@
     const int w = frame->width;
     const int h = frame->height;
     int i, ret;
+    int front = 0;
 
     if (is_inside(s->x, s->y, w, h)) {
         s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
@@ -310,9 +309,9 @@
             goto end;
 
         if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) {
-            s->points[s->front].x = s->x;
-            s->points[s->front].y = s->y;
-            s->front++;
+            s->points[front].x = s->x;
+            s->points[front].y = s->y;
+            front++;
         }
 
         if (ret = ff_inlink_make_frame_writable(link, &frame)) {
@@ -320,34 +319,34 @@
             return ret;
         }
 
-        while (s->front > s->back) {
+        while (front > 0) {
             int x, y;
 
-            s->front--;
-            x = s->points[s->front].x;
-            y = s->points[s->front].y;
+            front--;
+            x = s->points[front].x;
+            y = s->points[front].y;
 
             if (s->is_same(frame, x, y, s0, s1, s2, s3)) {
                 s->set_pixel(frame, x, y, d0, d1, d2, d3);
 
                 if (is_inside(x + 1, y, w, h)) {
-                    s->points[s->front]  .x = x + 1;
-                    s->points[s->front++].y = y;
+                    s->points[front]  .x = x + 1;
+                    s->points[front++].y = y;
                 }
 
                 if (is_inside(x - 1, y, w, h)) {
-                    s->points[s->front]  .x = x - 1;
-                    s->points[s->front++].y = y;
+                    s->points[front]  .x = x - 1;
+                    s->points[front++].y = y;
                 }
 
                 if (is_inside(x, y + 1, w, h)) {
-                    s->points[s->front]  .x = x;
-                    s->points[s->front++].y = y + 1;
+                    s->points[front]  .x = x;
+                    s->points[front++].y = y + 1;
                 }
 
                 if (is_inside(x, y - 1, w, h)) {
-                    s->points[s->front]  .x = x;
-                    s->points[s->front++].y = y - 1;
+                    s->points[front]  .x = x;
+                    s->points[front++].y = y - 1;
                 }
             }
         }

++++++ ffmpeg-8-CVE-2026-65706.patch ++++++
>From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sat, 11 Jul 2026 16:46:39 +0200
Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest
 plane

Fixes: out of array access
Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
Fixes: VRAXYvKtmKa8
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_swaprect.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c
index 5d93f51c30..fe007ee5e7 100644
--- a/libavfilter/vf_swaprect.c
+++ b/libavfilter/vf_swaprect.c
@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink)
 {
     AVFilterContext *ctx = inlink->dst;
     SwapRectContext *s = ctx->priv;
+    int size = 0;
 
     if (!s->w  || !s->h  ||
         !s->x1 || !s->y1 ||
@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink)
     av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc);
     s->nb_planes = av_pix_fmt_count_planes(inlink->format);
 
-    s->temp = av_malloc_array(inlink->w, s->pixsteps[0]);
+    for (int p = 0; p < s->nb_planes; p++) {
+        int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0;
+        int width = AV_CEIL_RSHIFT(inlink->w, shift);
+
+        if (width > INT_MAX / s->pixsteps[p])
+            return AVERROR(EINVAL);
+        size = FFMAX(size, width * s->pixsteps[p]);
+    }
+
+    s->temp = av_malloc(size);
     if (!s->temp)
         return AVERROR(ENOMEM);
 
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-66036-shim01.patch ++++++
>From e3d0c719fddd259709c8e275942ab56af3afc35d Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 13:05:07 +0200
Subject: [PATCH] avfilter/vf_hqdn3d: reject unsupported frame parameter
 changes

Fixes: out of array access
Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py
Fixes: wWDsy2oDvMuR
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++---------
 libavfilter/vf_hqdn3d.h |  2 ++
 2 files changed, 27 insertions(+), 9 deletions(-)

diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c
index d880c2bdda..70a2ec4628 100644
--- a/libavfilter/vf_hqdn3d.c
+++ b/libavfilter/vf_hqdn3d.c
@@ -163,12 +163,8 @@ static int denoise_depth(HQDN3DContext *s,
             case 14: ret = denoise_depth(__VA_ARGS__, 14); break;             \
             case 16: ret = denoise_depth(__VA_ARGS__, 16); break;             \
         }                                                                     \
-        if (ret < 0) {                                                        \
-            av_frame_free(&out);                                              \
-            if (!direct)                                                      \
-                av_frame_free(&in);                                           \
+        if (ret < 0)                                                          \
             return ret;                                                       \
-        }                                                                     \
     } while (0)
 
 static void precalc_coefs(double dist25, int depth, int16_t *ct)
@@ -281,12 +277,15 @@ static int config_input(AVFilterLink *inlink)
     ff_hqdn3d_init_x86(s);
 #endif
 
+    s->format = inlink->format;
+    s->width  = inlink->w;
+    s->height = inlink->h;
+
     return 0;
 }
 
 typedef struct ThreadData {
     AVFrame *in, *out;
-    int direct;
 } ThreadData;
 
 static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs)
@@ -295,7 +294,6 @@ static int do_denoise(AVFilterContext *ctx, void *data, int 
job_nr, int n_jobs)
     const ThreadData *td = data;
     AVFrame *out = td->out;
     AVFrame *in = td->in;
-    int direct = td->direct;
 
     denoise(s, in->data[job_nr], out->data[job_nr],
                 s->line[job_nr], &s->frame_prev[job_nr],
@@ -312,10 +310,21 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in)
 {
     AVFilterContext *ctx  = inlink->dst;
     AVFilterLink *outlink = ctx->outputs[0];
+    HQDN3DContext *s = ctx->priv;
 
     AVFrame *out;
     int direct = av_frame_is_writable(in) && !ctx->is_disabled;
     ThreadData td;
+    int ret[3];
+
+    if (in->format != s->format ||
+        in->width  != s->width  ||
+        in->height != s->height) {
+        av_log(ctx, AV_LOG_ERROR,
+               "Frame size or format changed without filter graph 
reinitialization\n");
+        av_frame_free(&in);
+        return AVERROR(EINVAL);
+    }
 
     if (direct) {
         out = in;
@@ -331,9 +340,16 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in)
 
     td.in = in;
     td.out = out;
-    td.direct = direct;
     /* one thread per plane */
-    ff_filter_execute(ctx, do_denoise, &td, NULL, 3);
+    ff_filter_execute(ctx, do_denoise, &td, ret, 3);
+    for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) {
+        if (ret[i] < 0) {
+            av_frame_free(&out);
+            if (!direct)
+                av_frame_free(&in);
+            return ret[i];
+        }
+    }
 
     if (ctx->is_disabled) {
         av_frame_free(&out);
diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h
index 3279bbcc77..3467f27145 100644
--- a/libavfilter/vf_hqdn3d.h
+++ b/libavfilter/vf_hqdn3d.h
@@ -36,6 +36,8 @@ typedef struct HQDN3DContext {
     double strength[4];
     int hsub, vsub;
     int depth;
+    int width, height;
+    enum AVPixelFormat format;
     void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, 
uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal);
 } HQDN3DContext;
 
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-66036.patch ++++++
>From 62294b6a8ad2370e1435bb9985ebe6b53be14c2b Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 13:05:33 +0200
Subject: [PATCH] avfilter/vf_hqdn3d: support dynamic frame sizes

(cherry picked from commit 5d7112c60e6f0f0742ce47d448e6da0718a70f4c)
---
 libavfilter/avfilter.c  |  3 ++-
 libavfilter/vf_hqdn3d.c | 21 ++++++++++++++-------
 2 files changed, 16 insertions(+), 8 deletions(-)

diff --git a/libavfilter/avfilter.c b/libavfilter/avfilter.c
index b15f0b08b4..2715f658b3 100644
--- a/libavfilter/avfilter.c
+++ b/libavfilter/avfilter.c
@@ -1078,7 +1078,8 @@ int ff_filter_frame(AVFilterLink *link, AVFrame *frame)
             strcmp(link->dst->filter->name, "idet") &&
             strcmp(link->dst->filter->name, "null") &&
             strcmp(link->dst->filter->name, "scale") &&
-            strcmp(link->dst->filter->name, "libplacebo")) {
+            strcmp(link->dst->filter->name, "libplacebo") &&
+            strcmp(link->dst->filter->name, "hqdn3d")) {
             av_assert1(frame->format        == link->format);
             av_assert1(frame->width         == link->w);
             av_assert1(frame->height        == link->h);
diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c
index 70a2ec4628..98c05e886c 100644
--- a/libavfilter/vf_hqdn3d.c
+++ b/libavfilter/vf_hqdn3d.c
@@ -315,21 +315,28 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in)
     AVFrame *out;
     int direct = av_frame_is_writable(in) && !ctx->is_disabled;
     ThreadData td;
-    int ret[3];
+    int err, ret[3];
 
-    if (in->format != s->format ||
-        in->width  != s->width  ||
-        in->height != s->height) {
-        av_log(ctx, AV_LOG_ERROR,
-               "Frame size or format changed without filter graph 
reinitialization\n");
+    if (in->format != s->format) {
         av_frame_free(&in);
         return AVERROR(EINVAL);
     }
 
+    if (in->width != s->width || in->height != s->height) {
+        inlink->w = in->width;
+        inlink->h = in->height;
+        if ((err = config_input(inlink)) < 0) {
+            av_frame_free(&in);
+            return err;
+        }
+        outlink->w = in->width;
+        outlink->h = in->height;
+    }
+
     if (direct) {
         out = in;
     } else {
-        out = ff_get_video_buffer(outlink, outlink->w, outlink->h);
+        out = ff_get_video_buffer(outlink, in->width, in->height);
         if (!out) {
             av_frame_free(&in);
             return AVERROR(ENOMEM);
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-66037.patch ++++++
>From f15e730cd225763bbae68614af777560aeb449dd Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 28 Jun 2026 22:05:28 +0200
Subject: [PATCH] avformat/iamf_parse: check count_label against the available
 bytes

Fixes: unbounded allocation / denial of service
Fixes: tP59h4cpaFyg
Fixes: 4ee05182b7 (avformat: Immersive Audio Model and Formats demuxer)
Found-by: Adrian Junge (vurlo)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 86708357d126af84c16f80d9c57335d1e8c845c5)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/iamf_parse.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/libavformat/iamf_parse.c b/libavformat/iamf_parse.c
index d74a8677d6..4c2df2c9e6 100644
--- a/libavformat/iamf_parse.c
+++ b/libavformat/iamf_parse.c
@@ -1009,6 +1009,11 @@ static int mix_presentation_obu(void *s, IAMFContext *c, 
AVIOContext *pb, int le
     mix_presentation->cmix = mix;
 
     mix_presentation->count_label = ffio_read_leb(pbc);
+    if (mix_presentation->count_label > len - avio_tell(pbc)) {
+        mix_presentation->count_label = 0;
+        ret = AVERROR_INVALIDDATA;
+        goto fail;
+    }
     mix_presentation->language_label = av_calloc(mix_presentation->count_label,
                                                  
sizeof(*mix_presentation->language_label));
     if (!mix_presentation->language_label) {
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-70628.patch ++++++
>From 02fc47e13f903768b75f7985a2706a6223ab4506 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:49:11 +0200
Subject: [PATCH] avcodec/dvbsub_parser: avoid signed overflow in the capacity
 check

Fixes: signed integer overflow
Fixes: out of array access
Fixes: poc.wtv
Fixes: fJeEU9JwKwsR
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 93f2a525ec6c7b467bae68322720d10188fc6e30)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/dvbsub_parser.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavcodec/dvbsub_parser.c b/libavcodec/dvbsub_parser.c
index 4527e4dd75..a93f39bfe0 100644
--- a/libavcodec/dvbsub_parser.c
+++ b/libavcodec/dvbsub_parser.c
@@ -104,7 +104,7 @@ static int dvbsub_parse(AVCodecParserContext *s,
         }
     }
 
-    if (buf_size - buf_pos + pc->packet_index > PARSE_BUF_SIZE)
+    if (buf_size - buf_pos > PARSE_BUF_SIZE - pc->packet_index)
         return buf_size;
 
 /* if not currently in a packet, pass data */
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-70629.patch ++++++
>From a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:03 +0200
Subject: [PATCH] avcodec/rscc: do not leave uninitilized data when the input
 is too short

Fixes: use of uninitialized memory
Fixes: rscc_short_deflate_heap_disclosure.avi
Fixes: plB80py3i3Bu
Found-by: Adrian Junge (vurlo)
(cherry picked from commit cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/rscc.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/libavcodec/rscc.c b/libavcodec/rscc.c
index 3715e1c6d4..5fde30ec35 100644
--- a/libavcodec/rscc.c
+++ b/libavcodec/rscc.c
@@ -311,6 +311,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
             ret = AVERROR_UNKNOWN;
             goto end;
         }
+        if (len < pixel_size) {
+            av_log(avctx, AV_LOG_WARNING, "Deflated %lu bytes, but %d are 
needed\n",
+                   len, pixel_size);
+            memset(ctx->inflated_buf + len, 0, pixel_size - len);
+            pixel_size = len;
+        }
         pixels = ctx->inflated_buf;
     }
 
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-70630.patch ++++++
>From c22667d0fd7916a33fd3e79685b7246fc48f1a62 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:41 +0200
Subject: [PATCH] avcodec/screenpresso: reject deflate output shorter than the
 frame

Fixes: use of uninitialized memory
Fixes: screenpresso_short_zlib_heap_disclosure.avi
Fixes: ksUBwBOjJodq
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 705890061467ad550ecc1dad5eea07f28ccfb43e)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/screenpresso.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c
index b27154991c..5864253d41 100644
--- a/libavcodec/screenpresso.c
+++ b/libavcodec/screenpresso.c
@@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
         return AVERROR_INVALIDDATA;
     }
 
+    /* Codec has aligned strides */
+    src_linesize = FFALIGN(avctx->width * component_size, 4);
+
     /* Inflate the frame after the 2 byte header */
     ret = uncompress(ctx->inflated_buf, &length,
                      avpkt->data + 2, avpkt->size - 2);
@@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext 
*avctx, AVFrame *frame,
         av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret);
         return AVERROR_UNKNOWN;
     }
+    if (length < src_linesize * avctx->height) {
+        av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n",
+               length, src_linesize * avctx->height);
+        return AVERROR_INVALIDDATA;
+    }
 
     ret = ff_reget_buffer(avctx, ctx->current, 0);
     if (ret < 0)
         return ret;
 
-    /* Codec has aligned strides */
-    src_linesize = FFALIGN(avctx->width * component_size, 4);
-
     /* When a keyframe is found, copy it (flipped) */
     if (keyframe)
         av_image_copy_plane(ctx->current->data[0] +
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-70631.patch ++++++
>From 3c287af3affe1286350faa69c02bcc5d49de18bb Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:41 +0200
Subject: [PATCH] avcodec/tiff: reject inflate output shorter than the strip

Fixes: use of uninitialized memory
Fixes: tiff_short_deflate_heap_disclosure.tiff
Fixes: 1cRIkpUVMQtn
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 2f234ea34c81288e3840fca632dd16481d8de39f)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/tiff.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c
index 8a179f0fd0..b8ce7b0b55 100644
--- a/libavcodec/tiff.c
+++ b/libavcodec/tiff.c
@@ -526,6 +526,7 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
     uint8_t *zbuf;
     unsigned long outlen;
     int ret, line;
+    int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : 
lines;
     outlen = width * lines;
     zbuf   = av_malloc(outlen);
     if (!zbuf)
@@ -545,6 +546,12 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
         av_free(zbuf);
         return AVERROR_UNKNOWN;
     }
+    if (outlen < (unsigned long)width * rows) {
+        av_log(s->avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %lu are 
needed\n",
+               outlen, (unsigned long)width * rows);
+        av_free(zbuf);
+        return AVERROR_INVALIDDATA;
+    }
     src = zbuf;
     for (line = 0; line < lines; line++) {
         if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) {
@@ -592,6 +599,7 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
 {
     uint64_t outlen = width * (uint64_t)lines;
     int ret, line;
+    int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : 
lines;
     uint8_t *buf = av_malloc(outlen);
     if (!buf)
         return AVERROR(ENOMEM);
@@ -610,6 +618,12 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
         av_free(buf);
         return AVERROR_UNKNOWN;
     }
+    if (outlen < (uint64_t)width * rows) {
+        av_log(s->avctx, AV_LOG_ERROR, "Uncompressed %"PRIu64" bytes, but 
%"PRIu64" are needed\n",
+               outlen, (uint64_t)width * rows);
+        av_free(buf);
+        return AVERROR_INVALIDDATA;
+    }
     src = buf;
     for (line = 0; line < lines; line++) {
         if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) {
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-70632.patch ++++++
>From 16b2049d4d5222db6cd7c031409058571c94f6a9 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:53:16 +0200
Subject: [PATCH] avcodec/cfhd: reject transform-2 output wider than the plane

Fixes: out of array access
Fixes: cfhd_transform2_output_width_oob.avi
Fixes: MimvoaEVpKow
Found-by: Adrian Junge (vurlo)
(cherry picked from commit db05df9d135fb56a4babb836d5e9f5c1d984e087)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/cfhd.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/libavcodec/cfhd.c b/libavcodec/cfhd.c
index 4d430e32ef..128362ac62 100644
--- a/libavcodec/cfhd.c
+++ b/libavcodec/cfhd.c
@@ -1224,7 +1224,7 @@ finish:
 
             if (lowpass_height > s->plane[plane].band[4][1].a_height || 
lowpass_width > s->plane[plane].band[4][1].a_width ||
                 !highpass_stride || s->plane[plane].band[4][1].width > 
s->plane[plane].band[4][1].a_width ||
-                lowpass_width < 3 || lowpass_height < 3) {
+                lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > 
s->plane[plane].width) {
                 av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n");
                 ret = AVERROR(EINVAL);
                 goto end;
@@ -1345,7 +1345,7 @@ finish:
 
             if (lowpass_height > s->plane[plane].band[4][1].a_height || 
lowpass_width > s->plane[plane].band[4][1].a_width ||
                 s->plane[plane].band[4][1].width > 
s->plane[plane].band[4][1].a_width ||
-                lowpass_width < 3 || lowpass_height < 3) {
+                lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > 
s->plane[plane].width) {
                 av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n");
                 ret = AVERROR(EINVAL);
                 goto end;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75141.patch ++++++
>From acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:56 +0000
Subject: [PATCH] avformat/hevc: reject hvcC NAL arrays that overflow the
 16-bit count

numNalus is uint16_t; a crafted hvcC declaring >65535 NAL units of one
type wraps it to 0 and then writes nal[-1]. Reject before the count can
wrap. Reachable by remuxing a crafted file with -c copy.

Fixes: integer overflow
Fixes: out of array access
---
 libavformat/hevc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/libavformat/hevc.c b/libavformat/hevc.c
index c9ee11f36c..678a9e2206 100644
--- a/libavformat/hevc.c
+++ b/libavformat/hevc.c
@@ -844,6 +844,9 @@ static int hvcc_array_add_nal_unit(const uint8_t *nal_buf, 
uint32_t nal_size,
     int ret;
     uint16_t numNalus = array->numNalus;
 
+    if (numNalus >= UINT16_MAX)
+        return AVERROR_INVALIDDATA;
+
     ret = av_reallocp_array(&array->nal, numNalus + 1, sizeof(*array->nal));
     if (ret < 0)
         return ret;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75142.patch ++++++
>From 9d786e4b5e9b8482651928574de33772aeee7be1 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/mpegenc: reject stream counts that overflow the
 system header

put_system_header() writes 12 + 3*N bytes after the pack header into a
fixed 128-byte stack buffer, but is handed a PutBitContext sized past the
real buffer, so its own bounds check never fires; ~35+ streams overflow the
stack. Reject at mux init when the system header would not fit.

Fixes: out of array access
Fixes: many.mkv
---
 libavformat/mpegenc.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/libavformat/mpegenc.c b/libavformat/mpegenc.c
index 128dfe2885..cea91d80da 100644
--- a/libavformat/mpegenc.c
+++ b/libavformat/mpegenc.c
@@ -473,6 +473,16 @@ static av_cold int mpeg_mux_init(AVFormatContext *ctx)
         if (!stream->fifo)
             return AVERROR(ENOMEM);
     }
+
+    /* The system header is emitted, right after the pack header (which is at
+     * most 14 bytes), into the fixed 128-byte buffer used by flush_packet().
+     * Reject configurations whose system header would not fit. */
+    if (get_system_header_size(ctx) > 128 - 14) {
+        av_log(ctx, AV_LOG_ERROR,
+               "Too many streams to fit the MPEG program stream system 
header\n");
+        return AVERROR(EINVAL);
+    }
+
     bitrate       = 0;
     audio_bitrate = 0;
     video_bitrate = 0;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75143.patch ++++++
>From 1c10bcc2e17255dacb717a25ab3db142ce390602 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/librist: honor the caller buffer size in
 librist_read

librist_read() ignored its size argument and copied the full payload_len,
overflowing a smaller destination (e.g. via the async: wrapper). Clamp the
copy to the caller-provided buffer size.

Fixes: out of array access
---
 libavformat/librist.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/librist.c b/libavformat/librist.c
index 9669d5b5df..3c4b5e3e5b 100644
--- a/libavformat/librist.c
+++ b/libavformat/librist.c
@@ -226,7 +226,7 @@ static int librist_read(URLContext *h, uint8_t *buf, int 
size)
         }
     }
 
-    size = data_block->payload_len;
+    size = FFMIN(data_block->payload_len, size);
     memcpy(buf, data_block->payload, size);
 out_free:
     rist_receiver_data_block_free2(&data_block);
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75144.patch ++++++
>From 1cdeb3c4e7f1f8566d846b9b451e01c376398818 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/rtpenc_vc2hq: reject data units larger than the RTP
 payload buffer

send_packet() copied an input-derived unit/fragment size into the fixed
rtp_ctx->buf with no bound, overflowing it for a crafted Dirac unit even at
the default packet size. Reject units that do not fit in max_payload_size.

Fixes: out of array access
---
 libavformat/rtpenc_vc2hq.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index cf548191d2..3b7147dfe2 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -33,16 +33,23 @@
 #define DIRAC_PIC_NR_SIZE                    4
 #define DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT      0xEC
 
-static void send_packet(AVFormatContext *ctx, uint8_t parse_code, int 
info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m)
+static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int 
info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m)
 {
     RTPMuxContext *rtp_ctx = ctx->priv_data;
 
+    if (size < 0 ||
+        size > rtp_ctx->max_payload_size - RTP_VC2HQ_PL_HEADER_SIZE - 
info_hdr_size) {
+        av_log(ctx, AV_LOG_ERROR, "VC-2 data unit too large for RTP payload 
buffer\n");
+        return AVERROR_INVALIDDATA;
+    }
+
     AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */
     AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: 
interlaced, second field */
     AV_WB8 (&rtp_ctx->buf[3], parse_code);
     if (size > 0)
         memcpy(&rtp_ctx->buf[4 + info_hdr_size], buf, size);
     ff_rtp_send_data(ctx, rtp_ctx->buf, RTP_VC2HQ_PL_HEADER_SIZE + 
info_hdr_size + size, rtp_m);
+    return 0;
 }
 
 static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, 
int interlaced)
@@ -85,7 +92,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t 
*buf, int size, int
     AV_WB16(&info_hdr[ 6], size_scaler);
     AV_WB16(&info_hdr[ 8], frag_len);
     AV_WB16(&info_hdr[10], 0 /* nr. of slices */);
-    send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, 
interlaced, second_field, 0);
+    if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, 
interlaced, second_field, 0) < 0)
+        return AVERROR_INVALIDDATA;
     buf += frag_len;
     size -= frag_len;
 
@@ -97,7 +105,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t 
*buf, int size, int
         AV_WB16(&info_hdr[14], 0 /* slice y */);
 
         size -= frag_len;
-        send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, 
interlaced, second_field, size > 0 ? 0 : 1);
+        if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, 
frag_len, interlaced, second_field, size > 0 ? 0 : 1) < 0)
+            return AVERROR_INVALIDDATA;
         buf += frag_len;
     }
     return 0;
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75145.patch ++++++
>From b4c199c5906ff53368926c2a5839881f41957e7f Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/rtpenc_av1: do not narrow the OBU size to (long)

(long)obu_size sign-flips values in 0x80000000..0xfffffffd on ILP32/LLP64
targets (32-bit long, e.g. 64-bit Windows), bypassing the size check.
Compare as uint32_t; frame_size is non-negative at this point.

No PoC as the used setup was 64bit specific
---
 libavformat/rtpenc_av1.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/rtpenc_av1.c b/libavformat/rtpenc_av1.c
index 934cfb63a3..f7c6aad47a 100644
--- a/libavformat/rtpenc_av1.c
+++ b/libavformat/rtpenc_av1.c
@@ -177,7 +177,7 @@ void ff_rtp_send_av1(AVFormatContext *ctx, const uint8_t 
*frame_buf, int frame_s
             return;
         }
 
-        if ((long) obu_size > frame_size) {
+        if (obu_size > (unsigned) frame_size) {
             av_log(ctx, AV_LOG_ERROR, "AV1 OBU size %d larger than remaining 
frame size %d\n", obu_size, frame_size);
             return;
         }
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75146.patch ++++++
>From 65b0dab903e5975e036b30ecc58f5935d4f151e0 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/dashdec: reject a negative fragment index

A live manifest whose startNumber decreases across a refresh drives
cur_seq_no negative in move_segments(); get_current_fragment() only checked
the upper bound before indexing fragments[]. Add a lower-bound check and
clamp the negative delta at its source.

Fixes: out of array read
---
 libavformat/dashdec.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/libavformat/dashdec.c b/libavformat/dashdec.c
index d4a05ace7e..740ac6bc1c 100644
--- a/libavformat/dashdec.c
+++ b/libavformat/dashdec.c
@@ -1537,8 +1537,11 @@ static void move_segments(struct representation 
*rep_src, struct representation
         free_fragment_list(rep_dest);
         if (rep_src->start_number > (rep_dest->start_number + 
rep_dest->n_fragments))
             rep_dest->cur_seq_no = 0;
-        else
+        else {
             rep_dest->cur_seq_no += rep_src->start_number - 
rep_dest->start_number;
+            if (rep_dest->cur_seq_no < 0)
+                rep_dest->cur_seq_no = 0;
+        }
         rep_dest->fragments    = rep_src->fragments;
         rep_dest->n_fragments  = rep_src->n_fragments;
         rep_dest->parent  = rep_src->parent;
@@ -1658,7 +1661,7 @@ static struct fragment *get_current_fragment(struct 
representation *pls)
     int reload_count = 0;
 
     while (( !ff_check_interrupt(c->interrupt_callback)&& pls->n_fragments > 
0)) {
-        if (pls->cur_seq_no < pls->n_fragments) {
+        if (pls->cur_seq_no >= 0 && pls->cur_seq_no < pls->n_fragments) {
             seg_ptr = pls->fragments[pls->cur_seq_no];
             seg = av_mallocz(sizeof(struct fragment));
             if (!seg) {
-- 
2.49.0


++++++ ffmpeg-8-CVE-2026-75147.patch ++++++
>From 983dae9c19f46c87d597598c0fd2f2fcee0ad2f8 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/rtpenc_av1: bound OBU size in the keyframe search
 loop

The is_keyframe sequence-header search loop advanced buf_ptr/rem_size by
num_lebs + obu_size without bounding obu_size against the remaining data
(unlike the main packetization loop). A crafted obu_size (~0x80000010)
wraps the signed rem_size back positive, so the next iteration
dereferences a pointer past the packet. Consume the LEB bytes first, then
reject an OBU larger than the remaining size. Out-of-bounds read reachable
from a crafted AV1 packet muxed to RTP.

Fixes: out of array read
---
 libavformat/rtpenc_av1.c | 11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

diff --git a/libavformat/rtpenc_av1.c b/libavformat/rtpenc_av1.c
index fbf9212216..ae66fdb86f 100644
--- a/libavformat/rtpenc_av1.c
+++ b/libavformat/rtpenc_av1.c
@@ -116,8 +116,15 @@ void ff_rtp_send_av1(AVFormatContext *ctx, const uint8_t 
*frame_buf, int frame_s
             if (!num_lebs) {
                 break;
             }
-            buf_ptr += num_lebs + obu_size;
-            rem_size -= num_lebs + obu_size;
+            buf_ptr += num_lebs;
+            rem_size -= num_lebs;
+            // bound OBU payload against remaining data to avoid pointer/size
+            // wraparound (mirrors the check in the packetization loop below)
+            if (obu_size > (uint32_t) rem_size) {
+                break;
+            }
+            buf_ptr += obu_size;
+            rem_size -= obu_size;
         }
 #else // RTPENC_AV1_SEARCH_SEQ_HEADER
         av_log(ctx, AV_LOG_DEBUG, "Marking FIRST packet\n");
-- 
2.49.0

Reply via email to