Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package ffmpeg-8 for openSUSE:Factory checked in at 2026-09-04 12:35:50 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/ffmpeg-8 (Old) and /work/SRC/openSUSE:Factory/.ffmpeg-8.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "ffmpeg-8" Fri Sep 4 12:35:50 2026 rev:15 rq:1375173 version:8.1.2 Changes: -------- --- /work/SRC/openSUSE:Factory/ffmpeg-8/ffmpeg-8.changes 2026-07-23 23:09:04.253607907 +0200 +++ /work/SRC/openSUSE:Factory/.ffmpeg-8.new.1265/ffmpeg-8.changes 2026-09-04 12:35:53.240054337 +0200 @@ -1,0 +2,188 @@ +Mon Aug 28 05:22:38 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75147.patch: + Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU + size in the keyframe search loop. + (CVE-2026-75147, bsc#1276413) + +------------------------------------------------------------------- +Mon Aug 28 04:47:54 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75146.patch: + Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative + fragment index. + (CVE-2026-75146, bsc#1276412) + +------------------------------------------------------------------- +Mon Aug 28 04:02:17 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75145.patch: + Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow + the OBU size to (long). + (CVE-2026-75145, bsc#1276411) + +------------------------------------------------------------------- +Mon Aug 28 03:34:50 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75144.patch: + Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data + units larger than the RTP payload buffer. + (CVE-2026-75144, bsc#1276410) + +------------------------------------------------------------------- +Mon Aug 28 03:17:21 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75143.patch: + Backport 1c10bcc2 from upstream, avformat/librist: honor the caller + buffer size in librist_read. + (CVE-2026-75143, bsc#1276409) + +------------------------------------------------------------------- +Mon Aug 28 02:58:12 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75142.patch: + Backport 9d786e4b from upstream, avformat/mpegenc: reject stream + counts that overflow the system header. + (CVE-2026-75142, bsc#1276408) + +------------------------------------------------------------------- +Mon Aug 28 02:44:56 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-75141.patch: + Backport acf5d7cd from upstream, avformat/hevc: reject hvcC + NAL arrays that overflow the 16-bit count. + (CVE-2026-75141, bsc#1276407) + +------------------------------------------------------------------- +Wed Aug 14 09:44:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-70632.patch: + Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 + output wider than the plane. + (CVE-2026-70632, bsc#1274289) + +------------------------------------------------------------------- +Wed Aug 14 08:27:41 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-70631.patch: + Backport 3c287af3 from upstream, avcodec/tiff: reject inflate + output shorter than the strip. + (CVE-2026-70631, bsc#1274287) + +------------------------------------------------------------------- +Wed Aug 14 07:58:24 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-70630.patch: + Backport c22667d0 from upstream, avcodec/screenpresso: reject + deflate output shorter than the frame. + (CVE-2026-70630, bsc#1274282) + +------------------------------------------------------------------- +Wed Aug 14 07:22:18 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-70629.patch: + Backport a5fe21a1 from upstream, avcodec/rscc: do not leave + uninitilized data when the input is too short. + (CVE-2026-70629, bsc#1274270) + +------------------------------------------------------------------- +Wed Aug 14 06:52:11 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-70628.patch: + Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid + signed overflow in the capacity check. + (CVE-2026-70628, bsc#1274268) + +------------------------------------------------------------------- +Wed Aug 14 06:41:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-66037.patch: + Backport f15e730c from upstream, avformat/iamf_parse: check + count_label against the available bytes. + (CVE-2026-66037, bsc#1272764) + +------------------------------------------------------------------- +Wed Aug 14 06:28:33 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-66036.patch: + Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support + dynamic frame sizes. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 05:51:42 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-66036-shim01.patch + Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject + unsupported frame parameter changes. This patch is for facilitate + ffmpeg-CVE-2026-66036.patch. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 05:31:22 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-65706.patch: + Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the + temp row buffer for the widest plane. + (CVE-2026-65706, bsc#1272762) + +------------------------------------------------------------------- +Wed Aug 14 04:56:09 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-65705.patch: + Backport 30a52276 from upstream, avfilter/vf_floodfill: remove + unneeded variables. + (CVE-2026-65705, bsc#1272761) + +------------------------------------------------------------------- +Wed Aug 14 04:31:19 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-65704.patch: + Backport 52f7983f from upstream, avformat/ty: don't let the Series2 + AC3 trim underflow the packet size. + (CVE-2026-65704, bsc#1272760) + +------------------------------------------------------------------- +Wed Aug 14 04:02:11 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-65703.patch: + Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference + frame before reallocating on size change. + (CVE-2026-65703, bsc#1272759) + +------------------------------------------------------------------- +Wed Aug 14 03:46:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-64834.patch: + Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF + objects smaller than their header. + (CVE-2026-64834, bsc#1272757) + +------------------------------------------------------------------- +Wed Aug 14 03:33:14 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-64833.patch: + Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS + core_size against the packet size in the HD path. + (CVE-2026-64833, bsc#1272755) + +------------------------------------------------------------------- +Wed Aug 14 03:28:13 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-8-CVE-2026-58049.patch: + Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit + DLTA accesses stay within the row. + (CVE-2026-58049, bsc#1269550) + +------------------------------------------------------------------- +Tue Aug 11 10:43:34 UTC 2026 - Jan Engelhardt <[email protected]> + +- Rename the ffmpeg BRPM back to ffmpeg-8 to make room for ffmpeg-9 + to fill the role. [boo#1271606] + +------------------------------------------------------------------- +Tue Jul 21 13:58:03 UTC 2026 - Jan Engelhardt <[email protected]> + +- Rename the ffmpeg-8 BRPM to ffmpeg. [boo#1271606] + +------------------------------------------------------------------- New: ---- ffmpeg-8-CVE-2026-58049.patch ffmpeg-8-CVE-2026-64833.patch ffmpeg-8-CVE-2026-64834.patch ffmpeg-8-CVE-2026-65703.patch ffmpeg-8-CVE-2026-65704.patch ffmpeg-8-CVE-2026-65705.patch ffmpeg-8-CVE-2026-65706.patch ffmpeg-8-CVE-2026-66036-shim01.patch ffmpeg-8-CVE-2026-66036.patch ffmpeg-8-CVE-2026-66037.patch ffmpeg-8-CVE-2026-70628.patch ffmpeg-8-CVE-2026-70629.patch ffmpeg-8-CVE-2026-70630.patch ffmpeg-8-CVE-2026-70631.patch ffmpeg-8-CVE-2026-70632.patch ffmpeg-8-CVE-2026-75141.patch ffmpeg-8-CVE-2026-75142.patch ffmpeg-8-CVE-2026-75143.patch ffmpeg-8-CVE-2026-75144.patch ffmpeg-8-CVE-2026-75145.patch ffmpeg-8-CVE-2026-75146.patch ffmpeg-8-CVE-2026-75147.patch ----------(New B)---------- New: - Add ffmpeg-8-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit New: - Add ffmpeg-8-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS New: - Add ffmpeg-8-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF New: - Add ffmpeg-8-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference New: - Add ffmpeg-8-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 New: - Add ffmpeg-8-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove New: - Add ffmpeg-8-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the New: - Add ffmpeg-8-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject New: - Add ffmpeg-8-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support New: - Add ffmpeg-8-CVE-2026-66037.patch: Backport f15e730c from upstream, avformat/iamf_parse: check New: - Add ffmpeg-8-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid New: - Add ffmpeg-8-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave New: - Add ffmpeg-8-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject New: - Add ffmpeg-8-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate New: - Add ffmpeg-8-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 New: - Add ffmpeg-8-CVE-2026-75141.patch: Backport acf5d7cd from upstream, avformat/hevc: reject hvcC New: - Add ffmpeg-8-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream New: - Add ffmpeg-8-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller New: - Add ffmpeg-8-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data New: - Add ffmpeg-8-CVE-2026-75145.patch: Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow New: - Add ffmpeg-8-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative New: - Add ffmpeg-8-CVE-2026-75147.patch: Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ ffmpeg-8.spec ++++++ --- /var/tmp/diff_new_pack.CWZjOR/_old 2026-09-04 12:35:55.068118520 +0200 +++ /var/tmp/diff_new_pack.CWZjOR/_new 2026-09-04 12:35:55.071118625 +0200 @@ -121,6 +121,28 @@ Patch5: work-around-abi-break.patch Patch10: ffmpeg-chromium.patch Patch15: 11013-avcodec-decode-clean-up-if-get_hw_frames_parameters-.patch +Patch16: ffmpeg-8-CVE-2026-58049.patch +Patch17: ffmpeg-8-CVE-2026-64833.patch +Patch18: ffmpeg-8-CVE-2026-64834.patch +Patch19: ffmpeg-8-CVE-2026-65703.patch +Patch20: ffmpeg-8-CVE-2026-65704.patch +Patch21: ffmpeg-8-CVE-2026-65705.patch +Patch22: ffmpeg-8-CVE-2026-65706.patch +Patch23: ffmpeg-8-CVE-2026-66036-shim01.patch +Patch24: ffmpeg-8-CVE-2026-66036.patch +Patch25: ffmpeg-8-CVE-2026-66037.patch +Patch26: ffmpeg-8-CVE-2026-70628.patch +Patch27: ffmpeg-8-CVE-2026-70629.patch +Patch28: ffmpeg-8-CVE-2026-70630.patch +Patch29: ffmpeg-8-CVE-2026-70631.patch +Patch30: ffmpeg-8-CVE-2026-70632.patch +Patch31: ffmpeg-8-CVE-2026-75141.patch +Patch32: ffmpeg-8-CVE-2026-75142.patch +Patch33: ffmpeg-8-CVE-2026-75143.patch +Patch34: ffmpeg-8-CVE-2026-75144.patch +Patch35: ffmpeg-8-CVE-2026-75145.patch +Patch36: ffmpeg-8-CVE-2026-75146.patch +Patch37: ffmpeg-8-CVE-2026-75147.patch BuildRequires: c++_compiler BuildRequires: ladspa-devel BuildRequires: libgsm-devel ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.CWZjOR/_old 2026-09-04 12:35:55.167121996 +0200 +++ /var/tmp/diff_new_pack.CWZjOR/_new 2026-09-04 12:35:55.171122136 +0200 @@ -1,5 +1,5 @@ -mtime: 1784610487 -commit: 8b01d1fdbd7368419bcce37a7eac79f1f1085d35bf059ee052dbdb2cde1ad90e +mtime: 1788270016 +commit: 404d61e94b16e44edc01e99a25f1b0f3318ce061cd57c23b075ad7188c2354b6 url: https://src.opensuse.org/jengelh/ffmpeg -revision: master +revision: ff8 ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-01 15:40:16.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ ffmpeg-8-CVE-2026-58049.patch ++++++ >From f8d7795dcca36a4dd412e89cbd83e3dfec1e0d81 Mon Sep 17 00:00:00 2001 From: Umar Pathan <[email protected]> Date: Sun, 28 Jun 2026 23:02:52 +0200 Subject: [PATCH] avcodec/rasc: Check that 32-bit DLTA accesses stay within the row Found-by: bikini (github.com/bikini/exploitarium) Fixes: out of array access Fixes: rowspill_128x1.avi / gen_rowspill_avi.py Fixes: xGV79bIb7uAJ (cherry picked from commit 11ff18a6c80187405fc492f9bb07ba9f2f663f76) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rasc.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/libavcodec/rasc.c b/libavcodec/rasc.c index 5f956a9b2c..d784a44063 100644 --- a/libavcodec/rasc.c +++ b/libavcodec/rasc.c @@ -320,6 +320,11 @@ static int decode_move(AVCodecContext *avctx, return 0; } +static inline int dlta_room(unsigned cx, unsigned w, unsigned bpp, unsigned need) +{ + return cx + need <= w * bpp; +} + #define NEXT_LINE \ if (cx >= w * s->bpp) { \ cx = 0; \ @@ -418,6 +423,8 @@ static int decode_dlta(AVCodecContext *avctx, case 4: fill = bytestream2_get_byte(&dc); while (len > 0 && cy > 0) { + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx++; @@ -427,6 +434,8 @@ static int decode_dlta(AVCodecContext *avctx, case 7: fill = bytestream2_get_le32(&dc); while (len > 0 && cy > 0) { + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx += 4; @@ -443,6 +452,8 @@ static int decode_dlta(AVCodecContext *avctx, while (len > 0 && cy > 0) { unsigned v0, v1; + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; v0 = AV_RL32(b2 + cx); v1 = AV_RL32(b1 + cx); AV_WL32(b2 + cx, v1); @@ -454,6 +465,8 @@ static int decode_dlta(AVCodecContext *avctx, case 13: while (len > 0 && cy > 0) { fill = bytestream2_get_le32(&dc); + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx += 4; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-64833.patch ++++++ >From 385ac2fadcb4394ec4f65e5c4d3d24003e090f36 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Tue, 30 Jun 2026 00:11:50 +0200 Subject: [PATCH] avformat/spdifenc: bound DTS core_size against the packet size in the HD path Fixes: out of array read Fixes: yBSax492UIB9 Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 6f80e2765492700622596af720534cef33dd31b4) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/spdifenc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c index ab3f73da0d..16eebda01c 100644 --- a/libavformat/spdifenc.c +++ b/libavformat/spdifenc.c @@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size, * (dtshd_fallback == 0) */ ctx->dtshd_skip = 1; } - if (ctx->dtshd_skip && core_size) { + if (ctx->dtshd_skip && core_size && core_size <= pkt->size) { pkt_size = core_size; if (ctx->dtshd_fallback >= 0) --ctx->dtshd_skip; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-64834.patch ++++++ >From 3c441711a343ccf50196c70a3f0b554b52f8d9de Mon Sep 17 00:00:00 2001 From: Pavel Kohout <[email protected]> Date: Tue, 30 Jun 2026 21:55:16 +0200 Subject: [PATCH] avformat/rtpdec_asf: reject ASF objects smaller than their header Fixes: infinite loop Fixes: MzWwJdpZF2Ls Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet parsing.) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 11d5f475be95d22d5f0692220cc772b116abc632) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/rtpdec_asf.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c index b3b346f3cc..f7fa69e27f 100644 --- a/libavformat/rtpdec_asf.c +++ b/libavformat/rtpdec_asf.c @@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len) uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid)); int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2; if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) { + if (chunksize < sizeof(ff_asf_guid) + 8) + return -1; if (chunksize > end - p) return -1; p += chunksize; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-65703.patch ++++++ >From 3b85fbe89025ea696988488358dfde41a09c53c5 Mon Sep 17 00:00:00 2001 From: Cloud-LHY <[email protected]> Date: Fri, 10 Jul 2026 04:07:04 +0200 Subject: [PATCH] avcodec/tdsc: unref the reference frame before reallocating on size change Fixes: out of array access Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py Fixes: p9xG4xGf9P7H Fixes: HQL7a1WgTdHZ Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS Found-by: Adrian Junge (vurlo) (cherry picked from commit fd3ee52fab34d98a95b787d0b5ff45685766200c) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/tdsc.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c index ca9dd0f0a6..102b4ae966 100644 --- a/libavcodec/tdsc.c +++ b/libavcodec/tdsc.c @@ -485,11 +485,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int number_tiles) return ret; init_refframe = 1; } - ctx->refframe->width = ctx->width = w; - ctx->refframe->height = ctx->height = h; + ctx->width = w; + ctx->height = h; /* Allocate the reference frame if not already done or on size change */ if (init_refframe) { + av_frame_unref(ctx->refframe); + ctx->refframe->format = avctx->pix_fmt; + ctx->refframe->width = w; + ctx->refframe->height = h; ret = av_frame_get_buffer(ctx->refframe, 0); if (ret < 0) return ret; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-65704.patch ++++++ >From 52f7983f15678c8a6065327760d7b6eb1c9c84ed Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Fri, 10 Jul 2026 04:07:35 +0200 Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the packet size Fixes: negative-size-param Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py Fixes: g0qeE6KvrjZi Found-by: Adrian Junge (vurlo) (cherry picked from commit de771bd52774a52d45b0e2c82e56995a1ef40df7) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/ty.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/ty.c b/libavformat/ty.c index 9be027fcca..842d97038c 100644 --- a/libavformat/ty.c +++ b/libavformat/ty.c @@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt) if (ty->audio_type == TIVO_AUDIO_AC3 && ty->tivo_series == TIVO_SERIES2) { if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) { - pkt->size -= 2; + pkt->size -= FFMIN(pkt->size, 2); ty->ac3_pkt_size = 0; } else { ty->ac3_pkt_size += pkt->size; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-65705.patch ++++++ >From 30a52276f9dff60fe732d8bb8d463e587ff69c94 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 03:27:47 +0200 Subject: [PATCH] avfilter/vf_floodfill: remove unneeded variables Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit f186c50cf53aec20e9a29059cb22ca3f2d59201c) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_floodfill.c | 35 ++++++++++++++++------------------- 1 file changed, 16 insertions(+), 19 deletions(-) diff a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c --- a/libavfilter/vf_floodfill.c +++ b/libavfilter/vf_floodfill.c @@ -39,7 +39,6 @@ int d[4]; int nb_planes; - int back, front; Points *points; int (*is_same)(const AVFrame *frame, int x, int y, @@ -270,7 +269,6 @@ } } - s->front = s->back = 0; s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points)); if (!s->points) return AVERROR(ENOMEM); @@ -293,6 +291,7 @@ const int w = frame->width; const int h = frame->height; int i, ret; + int front = 0; if (is_inside(s->x, s->y, w, h)) { s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); @@ -310,9 +309,9 @@ goto end; if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) { - s->points[s->front].x = s->x; - s->points[s->front].y = s->y; - s->front++; + s->points[front].x = s->x; + s->points[front].y = s->y; + front++; } if (ret = ff_inlink_make_frame_writable(link, &frame)) { @@ -320,34 +319,34 @@ return ret; } - while (s->front > s->back) { + while (front > 0) { int x, y; - s->front--; - x = s->points[s->front].x; - y = s->points[s->front].y; + front--; + x = s->points[front].x; + y = s->points[front].y; if (s->is_same(frame, x, y, s0, s1, s2, s3)) { s->set_pixel(frame, x, y, d0, d1, d2, d3); if (is_inside(x + 1, y, w, h)) { - s->points[s->front] .x = x + 1; - s->points[s->front++].y = y; + s->points[front] .x = x + 1; + s->points[front++].y = y; } if (is_inside(x - 1, y, w, h)) { - s->points[s->front] .x = x - 1; - s->points[s->front++].y = y; + s->points[front] .x = x - 1; + s->points[front++].y = y; } if (is_inside(x, y + 1, w, h)) { - s->points[s->front] .x = x; - s->points[s->front++].y = y + 1; + s->points[front] .x = x; + s->points[front++].y = y + 1; } if (is_inside(x, y - 1, w, h)) { - s->points[s->front] .x = x; - s->points[s->front++].y = y - 1; + s->points[front] .x = x; + s->points[front++].y = y - 1; } } } ++++++ ffmpeg-8-CVE-2026-65706.patch ++++++ >From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sat, 11 Jul 2026 16:46:39 +0200 Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest plane Fixes: out of array access Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py Fixes: VRAXYvKtmKa8 Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_swaprect.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c index 5d93f51c30..fe007ee5e7 100644 --- a/libavfilter/vf_swaprect.c +++ b/libavfilter/vf_swaprect.c @@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink) { AVFilterContext *ctx = inlink->dst; SwapRectContext *s = ctx->priv; + int size = 0; if (!s->w || !s->h || !s->x1 || !s->y1 || @@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink) av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc); s->nb_planes = av_pix_fmt_count_planes(inlink->format); - s->temp = av_malloc_array(inlink->w, s->pixsteps[0]); + for (int p = 0; p < s->nb_planes; p++) { + int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0; + int width = AV_CEIL_RSHIFT(inlink->w, shift); + + if (width > INT_MAX / s->pixsteps[p]) + return AVERROR(EINVAL); + size = FFMAX(size, width * s->pixsteps[p]); + } + + s->temp = av_malloc(size); if (!s->temp) return AVERROR(ENOMEM); -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-66036-shim01.patch ++++++ >From e3d0c719fddd259709c8e275942ab56af3afc35d Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 13:05:07 +0200 Subject: [PATCH] avfilter/vf_hqdn3d: reject unsupported frame parameter changes Fixes: out of array access Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py Fixes: wWDsy2oDvMuR Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++--------- libavfilter/vf_hqdn3d.h | 2 ++ 2 files changed, 27 insertions(+), 9 deletions(-) diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c index d880c2bdda..70a2ec4628 100644 --- a/libavfilter/vf_hqdn3d.c +++ b/libavfilter/vf_hqdn3d.c @@ -163,12 +163,8 @@ static int denoise_depth(HQDN3DContext *s, case 14: ret = denoise_depth(__VA_ARGS__, 14); break; \ case 16: ret = denoise_depth(__VA_ARGS__, 16); break; \ } \ - if (ret < 0) { \ - av_frame_free(&out); \ - if (!direct) \ - av_frame_free(&in); \ + if (ret < 0) \ return ret; \ - } \ } while (0) static void precalc_coefs(double dist25, int depth, int16_t *ct) @@ -281,12 +277,15 @@ static int config_input(AVFilterLink *inlink) ff_hqdn3d_init_x86(s); #endif + s->format = inlink->format; + s->width = inlink->w; + s->height = inlink->h; + return 0; } typedef struct ThreadData { AVFrame *in, *out; - int direct; } ThreadData; static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) @@ -295,7 +294,6 @@ static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) const ThreadData *td = data; AVFrame *out = td->out; AVFrame *in = td->in; - int direct = td->direct; denoise(s, in->data[job_nr], out->data[job_nr], s->line[job_nr], &s->frame_prev[job_nr], @@ -312,10 +310,21 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) { AVFilterContext *ctx = inlink->dst; AVFilterLink *outlink = ctx->outputs[0]; + HQDN3DContext *s = ctx->priv; AVFrame *out; int direct = av_frame_is_writable(in) && !ctx->is_disabled; ThreadData td; + int ret[3]; + + if (in->format != s->format || + in->width != s->width || + in->height != s->height) { + av_log(ctx, AV_LOG_ERROR, + "Frame size or format changed without filter graph reinitialization\n"); + av_frame_free(&in); + return AVERROR(EINVAL); + } if (direct) { out = in; @@ -331,9 +340,16 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) td.in = in; td.out = out; - td.direct = direct; /* one thread per plane */ - ff_filter_execute(ctx, do_denoise, &td, NULL, 3); + ff_filter_execute(ctx, do_denoise, &td, ret, 3); + for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) { + if (ret[i] < 0) { + av_frame_free(&out); + if (!direct) + av_frame_free(&in); + return ret[i]; + } + } if (ctx->is_disabled) { av_frame_free(&out); diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h index 3279bbcc77..3467f27145 100644 --- a/libavfilter/vf_hqdn3d.h +++ b/libavfilter/vf_hqdn3d.h @@ -36,6 +36,8 @@ typedef struct HQDN3DContext { double strength[4]; int hsub, vsub; int depth; + int width, height; + enum AVPixelFormat format; void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal); } HQDN3DContext; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-66036.patch ++++++ >From 62294b6a8ad2370e1435bb9985ebe6b53be14c2b Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 13:05:33 +0200 Subject: [PATCH] avfilter/vf_hqdn3d: support dynamic frame sizes (cherry picked from commit 5d7112c60e6f0f0742ce47d448e6da0718a70f4c) --- libavfilter/avfilter.c | 3 ++- libavfilter/vf_hqdn3d.c | 21 ++++++++++++++------- 2 files changed, 16 insertions(+), 8 deletions(-) diff --git a/libavfilter/avfilter.c b/libavfilter/avfilter.c index b15f0b08b4..2715f658b3 100644 --- a/libavfilter/avfilter.c +++ b/libavfilter/avfilter.c @@ -1078,7 +1078,8 @@ int ff_filter_frame(AVFilterLink *link, AVFrame *frame) strcmp(link->dst->filter->name, "idet") && strcmp(link->dst->filter->name, "null") && strcmp(link->dst->filter->name, "scale") && - strcmp(link->dst->filter->name, "libplacebo")) { + strcmp(link->dst->filter->name, "libplacebo") && + strcmp(link->dst->filter->name, "hqdn3d")) { av_assert1(frame->format == link->format); av_assert1(frame->width == link->w); av_assert1(frame->height == link->h); diff --git a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c index 70a2ec4628..98c05e886c 100644 --- a/libavfilter/vf_hqdn3d.c +++ b/libavfilter/vf_hqdn3d.c @@ -315,21 +315,28 @@ static int filter_frame(AVFilterLink *inlink, AVFrame *in) AVFrame *out; int direct = av_frame_is_writable(in) && !ctx->is_disabled; ThreadData td; - int ret[3]; + int err, ret[3]; - if (in->format != s->format || - in->width != s->width || - in->height != s->height) { - av_log(ctx, AV_LOG_ERROR, - "Frame size or format changed without filter graph reinitialization\n"); + if (in->format != s->format) { av_frame_free(&in); return AVERROR(EINVAL); } + if (in->width != s->width || in->height != s->height) { + inlink->w = in->width; + inlink->h = in->height; + if ((err = config_input(inlink)) < 0) { + av_frame_free(&in); + return err; + } + outlink->w = in->width; + outlink->h = in->height; + } + if (direct) { out = in; } else { - out = ff_get_video_buffer(outlink, outlink->w, outlink->h); + out = ff_get_video_buffer(outlink, in->width, in->height); if (!out) { av_frame_free(&in); return AVERROR(ENOMEM); -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-66037.patch ++++++ >From f15e730cd225763bbae68614af777560aeb449dd Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 28 Jun 2026 22:05:28 +0200 Subject: [PATCH] avformat/iamf_parse: check count_label against the available bytes Fixes: unbounded allocation / denial of service Fixes: tP59h4cpaFyg Fixes: 4ee05182b7 (avformat: Immersive Audio Model and Formats demuxer) Found-by: Adrian Junge (vurlo) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 86708357d126af84c16f80d9c57335d1e8c845c5) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/iamf_parse.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/libavformat/iamf_parse.c b/libavformat/iamf_parse.c index d74a8677d6..4c2df2c9e6 100644 --- a/libavformat/iamf_parse.c +++ b/libavformat/iamf_parse.c @@ -1009,6 +1009,11 @@ static int mix_presentation_obu(void *s, IAMFContext *c, AVIOContext *pb, int le mix_presentation->cmix = mix; mix_presentation->count_label = ffio_read_leb(pbc); + if (mix_presentation->count_label > len - avio_tell(pbc)) { + mix_presentation->count_label = 0; + ret = AVERROR_INVALIDDATA; + goto fail; + } mix_presentation->language_label = av_calloc(mix_presentation->count_label, sizeof(*mix_presentation->language_label)); if (!mix_presentation->language_label) { -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-70628.patch ++++++ >From 02fc47e13f903768b75f7985a2706a6223ab4506 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:49:11 +0200 Subject: [PATCH] avcodec/dvbsub_parser: avoid signed overflow in the capacity check Fixes: signed integer overflow Fixes: out of array access Fixes: poc.wtv Fixes: fJeEU9JwKwsR Found-by: Adrian Junge (vurlo) (cherry picked from commit 93f2a525ec6c7b467bae68322720d10188fc6e30) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/dvbsub_parser.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/dvbsub_parser.c b/libavcodec/dvbsub_parser.c index 4527e4dd75..a93f39bfe0 100644 --- a/libavcodec/dvbsub_parser.c +++ b/libavcodec/dvbsub_parser.c @@ -104,7 +104,7 @@ static int dvbsub_parse(AVCodecParserContext *s, } } - if (buf_size - buf_pos + pc->packet_index > PARSE_BUF_SIZE) + if (buf_size - buf_pos > PARSE_BUF_SIZE - pc->packet_index) return buf_size; /* if not currently in a packet, pass data */ -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-70629.patch ++++++ >From a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:03 +0200 Subject: [PATCH] avcodec/rscc: do not leave uninitilized data when the input is too short Fixes: use of uninitialized memory Fixes: rscc_short_deflate_heap_disclosure.avi Fixes: plB80py3i3Bu Found-by: Adrian Junge (vurlo) (cherry picked from commit cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rscc.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/libavcodec/rscc.c b/libavcodec/rscc.c index 3715e1c6d4..5fde30ec35 100644 --- a/libavcodec/rscc.c +++ b/libavcodec/rscc.c @@ -311,6 +311,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, AVFrame *frame, ret = AVERROR_UNKNOWN; goto end; } + if (len < pixel_size) { + av_log(avctx, AV_LOG_WARNING, "Deflated %lu bytes, but %d are needed\n", + len, pixel_size); + memset(ctx->inflated_buf + len, 0, pixel_size - len); + pixel_size = len; + } pixels = ctx->inflated_buf; } -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-70630.patch ++++++ >From c22667d0fd7916a33fd3e79685b7246fc48f1a62 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:41 +0200 Subject: [PATCH] avcodec/screenpresso: reject deflate output shorter than the frame Fixes: use of uninitialized memory Fixes: screenpresso_short_zlib_heap_disclosure.avi Fixes: ksUBwBOjJodq Found-by: Adrian Junge (vurlo) (cherry picked from commit 705890061467ad550ecc1dad5eea07f28ccfb43e) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/screenpresso.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c index b27154991c..5864253d41 100644 --- a/libavcodec/screenpresso.c +++ b/libavcodec/screenpresso.c @@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame, return AVERROR_INVALIDDATA; } + /* Codec has aligned strides */ + src_linesize = FFALIGN(avctx->width * component_size, 4); + /* Inflate the frame after the 2 byte header */ ret = uncompress(ctx->inflated_buf, &length, avpkt->data + 2, avpkt->size - 2); @@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame, av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret); return AVERROR_UNKNOWN; } + if (length < src_linesize * avctx->height) { + av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n", + length, src_linesize * avctx->height); + return AVERROR_INVALIDDATA; + } ret = ff_reget_buffer(avctx, ctx->current, 0); if (ret < 0) return ret; - /* Codec has aligned strides */ - src_linesize = FFALIGN(avctx->width * component_size, 4); - /* When a keyframe is found, copy it (flipped) */ if (keyframe) av_image_copy_plane(ctx->current->data[0] + -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-70631.patch ++++++ >From 3c287af3affe1286350faa69c02bcc5d49de18bb Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:41 +0200 Subject: [PATCH] avcodec/tiff: reject inflate output shorter than the strip Fixes: use of uninitialized memory Fixes: tiff_short_deflate_heap_disclosure.tiff Fixes: 1cRIkpUVMQtn Found-by: Adrian Junge (vurlo) (cherry picked from commit 2f234ea34c81288e3840fca632dd16481d8de39f) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/tiff.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c index 8a179f0fd0..b8ce7b0b55 100644 --- a/libavcodec/tiff.c +++ b/libavcodec/tiff.c @@ -526,6 +526,7 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, uint8_t *dst, int stride uint8_t *zbuf; unsigned long outlen; int ret, line; + int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : lines; outlen = width * lines; zbuf = av_malloc(outlen); if (!zbuf) @@ -545,6 +546,12 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, uint8_t *dst, int stride av_free(zbuf); return AVERROR_UNKNOWN; } + if (outlen < (unsigned long)width * rows) { + av_log(s->avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %lu are needed\n", + outlen, (unsigned long)width * rows); + av_free(zbuf); + return AVERROR_INVALIDDATA; + } src = zbuf; for (line = 0; line < lines; line++) { if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) { @@ -592,6 +599,7 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, uint8_t *dst, int stride { uint64_t outlen = width * (uint64_t)lines; int ret, line; + int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : lines; uint8_t *buf = av_malloc(outlen); if (!buf) return AVERROR(ENOMEM); @@ -610,6 +618,12 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, uint8_t *dst, int stride av_free(buf); return AVERROR_UNKNOWN; } + if (outlen < (uint64_t)width * rows) { + av_log(s->avctx, AV_LOG_ERROR, "Uncompressed %"PRIu64" bytes, but %"PRIu64" are needed\n", + outlen, (uint64_t)width * rows); + av_free(buf); + return AVERROR_INVALIDDATA; + } src = buf; for (line = 0; line < lines; line++) { if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) { -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-70632.patch ++++++ >From 16b2049d4d5222db6cd7c031409058571c94f6a9 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:53:16 +0200 Subject: [PATCH] avcodec/cfhd: reject transform-2 output wider than the plane Fixes: out of array access Fixes: cfhd_transform2_output_width_oob.avi Fixes: MimvoaEVpKow Found-by: Adrian Junge (vurlo) (cherry picked from commit db05df9d135fb56a4babb836d5e9f5c1d984e087) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/cfhd.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/libavcodec/cfhd.c b/libavcodec/cfhd.c index 4d430e32ef..128362ac62 100644 --- a/libavcodec/cfhd.c +++ b/libavcodec/cfhd.c @@ -1224,7 +1224,7 @@ finish: if (lowpass_height > s->plane[plane].band[4][1].a_height || lowpass_width > s->plane[plane].band[4][1].a_width || !highpass_stride || s->plane[plane].band[4][1].width > s->plane[plane].band[4][1].a_width || - lowpass_width < 3 || lowpass_height < 3) { + lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > s->plane[plane].width) { av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n"); ret = AVERROR(EINVAL); goto end; @@ -1345,7 +1345,7 @@ finish: if (lowpass_height > s->plane[plane].band[4][1].a_height || lowpass_width > s->plane[plane].band[4][1].a_width || s->plane[plane].band[4][1].width > s->plane[plane].band[4][1].a_width || - lowpass_width < 3 || lowpass_height < 3) { + lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > s->plane[plane].width) { av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n"); ret = AVERROR(EINVAL); goto end; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75141.patch ++++++ >From acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:56 +0000 Subject: [PATCH] avformat/hevc: reject hvcC NAL arrays that overflow the 16-bit count numNalus is uint16_t; a crafted hvcC declaring >65535 NAL units of one type wraps it to 0 and then writes nal[-1]. Reject before the count can wrap. Reachable by remuxing a crafted file with -c copy. Fixes: integer overflow Fixes: out of array access --- libavformat/hevc.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/libavformat/hevc.c b/libavformat/hevc.c index c9ee11f36c..678a9e2206 100644 --- a/libavformat/hevc.c +++ b/libavformat/hevc.c @@ -844,6 +844,9 @@ static int hvcc_array_add_nal_unit(const uint8_t *nal_buf, uint32_t nal_size, int ret; uint16_t numNalus = array->numNalus; + if (numNalus >= UINT16_MAX) + return AVERROR_INVALIDDATA; + ret = av_reallocp_array(&array->nal, numNalus + 1, sizeof(*array->nal)); if (ret < 0) return ret; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75142.patch ++++++ >From 9d786e4b5e9b8482651928574de33772aeee7be1 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/mpegenc: reject stream counts that overflow the system header put_system_header() writes 12 + 3*N bytes after the pack header into a fixed 128-byte stack buffer, but is handed a PutBitContext sized past the real buffer, so its own bounds check never fires; ~35+ streams overflow the stack. Reject at mux init when the system header would not fit. Fixes: out of array access Fixes: many.mkv --- libavformat/mpegenc.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/libavformat/mpegenc.c b/libavformat/mpegenc.c index 128dfe2885..cea91d80da 100644 --- a/libavformat/mpegenc.c +++ b/libavformat/mpegenc.c @@ -473,6 +473,16 @@ static av_cold int mpeg_mux_init(AVFormatContext *ctx) if (!stream->fifo) return AVERROR(ENOMEM); } + + /* The system header is emitted, right after the pack header (which is at + * most 14 bytes), into the fixed 128-byte buffer used by flush_packet(). + * Reject configurations whose system header would not fit. */ + if (get_system_header_size(ctx) > 128 - 14) { + av_log(ctx, AV_LOG_ERROR, + "Too many streams to fit the MPEG program stream system header\n"); + return AVERROR(EINVAL); + } + bitrate = 0; audio_bitrate = 0; video_bitrate = 0; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75143.patch ++++++ >From 1c10bcc2e17255dacb717a25ab3db142ce390602 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/librist: honor the caller buffer size in librist_read librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination (e.g. via the async: wrapper). Clamp the copy to the caller-provided buffer size. Fixes: out of array access --- libavformat/librist.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/librist.c b/libavformat/librist.c index 9669d5b5df..3c4b5e3e5b 100644 --- a/libavformat/librist.c +++ b/libavformat/librist.c @@ -226,7 +226,7 @@ static int librist_read(URLContext *h, uint8_t *buf, int size) } } - size = data_block->payload_len; + size = FFMIN(data_block->payload_len, size); memcpy(buf, data_block->payload, size); out_free: rist_receiver_data_block_free2(&data_block); -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75144.patch ++++++ >From 1cdeb3c4e7f1f8566d846b9b451e01c376398818 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer send_packet() copied an input-derived unit/fragment size into the fixed rtp_ctx->buf with no bound, overflowing it for a crafted Dirac unit even at the default packet size. Reject units that do not fit in max_payload_size. Fixes: out of array access --- libavformat/rtpenc_vc2hq.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c index cf548191d2..3b7147dfe2 100644 --- a/libavformat/rtpenc_vc2hq.c +++ b/libavformat/rtpenc_vc2hq.c @@ -33,16 +33,23 @@ #define DIRAC_PIC_NR_SIZE 4 #define DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT 0xEC -static void send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m) +static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m) { RTPMuxContext *rtp_ctx = ctx->priv_data; + if (size < 0 || + size > rtp_ctx->max_payload_size - RTP_VC2HQ_PL_HEADER_SIZE - info_hdr_size) { + av_log(ctx, AV_LOG_ERROR, "VC-2 data unit too large for RTP payload buffer\n"); + return AVERROR_INVALIDDATA; + } + AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */ AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: interlaced, second field */ AV_WB8 (&rtp_ctx->buf[3], parse_code); if (size > 0) memcpy(&rtp_ctx->buf[4 + info_hdr_size], buf, size); ff_rtp_send_data(ctx, rtp_ctx->buf, RTP_VC2HQ_PL_HEADER_SIZE + info_hdr_size + size, rtp_m); + return 0; } static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int interlaced) @@ -85,7 +92,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int AV_WB16(&info_hdr[ 6], size_scaler); AV_WB16(&info_hdr[ 8], frag_len); AV_WB16(&info_hdr[10], 0 /* nr. of slices */); - send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, interlaced, second_field, 0); + if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, interlaced, second_field, 0) < 0) + return AVERROR_INVALIDDATA; buf += frag_len; size -= frag_len; @@ -97,7 +105,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int AV_WB16(&info_hdr[14], 0 /* slice y */); size -= frag_len; - send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, interlaced, second_field, size > 0 ? 0 : 1); + if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, interlaced, second_field, size > 0 ? 0 : 1) < 0) + return AVERROR_INVALIDDATA; buf += frag_len; } return 0; -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75145.patch ++++++ >From b4c199c5906ff53368926c2a5839881f41957e7f Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/rtpenc_av1: do not narrow the OBU size to (long) (long)obu_size sign-flips values in 0x80000000..0xfffffffd on ILP32/LLP64 targets (32-bit long, e.g. 64-bit Windows), bypassing the size check. Compare as uint32_t; frame_size is non-negative at this point. No PoC as the used setup was 64bit specific --- libavformat/rtpenc_av1.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/rtpenc_av1.c b/libavformat/rtpenc_av1.c index 934cfb63a3..f7c6aad47a 100644 --- a/libavformat/rtpenc_av1.c +++ b/libavformat/rtpenc_av1.c @@ -177,7 +177,7 @@ void ff_rtp_send_av1(AVFormatContext *ctx, const uint8_t *frame_buf, int frame_s return; } - if ((long) obu_size > frame_size) { + if (obu_size > (unsigned) frame_size) { av_log(ctx, AV_LOG_ERROR, "AV1 OBU size %d larger than remaining frame size %d\n", obu_size, frame_size); return; } -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75146.patch ++++++ >From 65b0dab903e5975e036b30ecc58f5935d4f151e0 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/dashdec: reject a negative fragment index A live manifest whose startNumber decreases across a refresh drives cur_seq_no negative in move_segments(); get_current_fragment() only checked the upper bound before indexing fragments[]. Add a lower-bound check and clamp the negative delta at its source. Fixes: out of array read --- libavformat/dashdec.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/libavformat/dashdec.c b/libavformat/dashdec.c index d4a05ace7e..740ac6bc1c 100644 --- a/libavformat/dashdec.c +++ b/libavformat/dashdec.c @@ -1537,8 +1537,11 @@ static void move_segments(struct representation *rep_src, struct representation free_fragment_list(rep_dest); if (rep_src->start_number > (rep_dest->start_number + rep_dest->n_fragments)) rep_dest->cur_seq_no = 0; - else + else { rep_dest->cur_seq_no += rep_src->start_number - rep_dest->start_number; + if (rep_dest->cur_seq_no < 0) + rep_dest->cur_seq_no = 0; + } rep_dest->fragments = rep_src->fragments; rep_dest->n_fragments = rep_src->n_fragments; rep_dest->parent = rep_src->parent; @@ -1658,7 +1661,7 @@ static struct fragment *get_current_fragment(struct representation *pls) int reload_count = 0; while (( !ff_check_interrupt(c->interrupt_callback)&& pls->n_fragments > 0)) { - if (pls->cur_seq_no < pls->n_fragments) { + if (pls->cur_seq_no >= 0 && pls->cur_seq_no < pls->n_fragments) { seg_ptr = pls->fragments[pls->cur_seq_no]; seg = av_mallocz(sizeof(struct fragment)); if (!seg) { -- 2.49.0 ++++++ ffmpeg-8-CVE-2026-75147.patch ++++++ >From 983dae9c19f46c87d597598c0fd2f2fcee0ad2f8 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/rtpenc_av1: bound OBU size in the keyframe search loop The is_keyframe sequence-header search loop advanced buf_ptr/rem_size by num_lebs + obu_size without bounding obu_size against the remaining data (unlike the main packetization loop). A crafted obu_size (~0x80000010) wraps the signed rem_size back positive, so the next iteration dereferences a pointer past the packet. Consume the LEB bytes first, then reject an OBU larger than the remaining size. Out-of-bounds read reachable from a crafted AV1 packet muxed to RTP. Fixes: out of array read --- libavformat/rtpenc_av1.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/libavformat/rtpenc_av1.c b/libavformat/rtpenc_av1.c index fbf9212216..ae66fdb86f 100644 --- a/libavformat/rtpenc_av1.c +++ b/libavformat/rtpenc_av1.c @@ -116,8 +116,15 @@ void ff_rtp_send_av1(AVFormatContext *ctx, const uint8_t *frame_buf, int frame_s if (!num_lebs) { break; } - buf_ptr += num_lebs + obu_size; - rem_size -= num_lebs + obu_size; + buf_ptr += num_lebs; + rem_size -= num_lebs; + // bound OBU payload against remaining data to avoid pointer/size + // wraparound (mirrors the check in the packetization loop below) + if (obu_size > (uint32_t) rem_size) { + break; + } + buf_ptr += obu_size; + rem_size -= obu_size; } #else // RTPENC_AV1_SEARCH_SEQ_HEADER av_log(ctx, AV_LOG_DEBUG, "Marking FIRST packet\n"); -- 2.49.0
