Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package ffmpeg-4 for openSUSE:Factory 
checked in at 2026-09-08 16:53:46
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/ffmpeg-4 (Old)
 and      /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "ffmpeg-4"

Tue Sep  8 16:53:46 2026 rev:100 rq:1376009 version:4.4.8

Changes:
--------
--- /work/SRC/openSUSE:Factory/ffmpeg-4/ffmpeg-4.changes        2026-08-21 
17:02:44.837081543 +0200
+++ /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1265/ffmpeg-4.changes      
2026-09-08 16:54:38.885301431 +0200
@@ -1,0 +2,72 @@
+Mon Aug 28 04:47:54 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-75146.patch:
+  Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative
+  fragment index.
+  (CVE-2026-75146, bsc#1276412)
+
+-------------------------------------------------------------------
+Mon Aug 28 03:34:50 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-75144.patch:
+  Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data
+  units larger than the RTP payload buffer.
+  (CVE-2026-75144, bsc#1276410)
+
+-------------------------------------------------------------------
+Mon Aug 28 03:17:21 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-75143.patch:
+  Backport 1c10bcc2 from upstream, avformat/librist: honor the caller
+  buffer size in librist_read.
+  (CVE-2026-75143, bsc#1276409)
+
+-------------------------------------------------------------------
+Mon Aug 28 02:58:12 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-75142.patch:
+  Backport 9d786e4b from upstream, avformat/mpegenc: reject stream
+  counts that overflow the system header.
+  (CVE-2026-75142, bsc#1276408)
+
+-------------------------------------------------------------------
+Wed Aug 14 09:44:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-70632.patch:
+  Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2
+  output wider than the plane.
+  (CVE-2026-70632, bsc#1274289)
+
+-------------------------------------------------------------------
+Wed Aug 14 08:27:41 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-70631.patch:
+  Backport 3c287af3 from upstream, avcodec/tiff: reject inflate
+  output shorter than the strip.
+  (CVE-2026-70631, bsc#1274287)
+
+-------------------------------------------------------------------
+Wed Aug 14 07:58:24 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-70630.patch:
+  Backport c22667d0 from upstream, avcodec/screenpresso: reject
+  deflate output shorter than the frame.
+  (CVE-2026-70630, bsc#1274282)
+
+-------------------------------------------------------------------
+Wed Aug 14 07:22:18 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-70629.patch:
+  Backport a5fe21a1 from upstream, avcodec/rscc: do not leave
+  uninitilized data when the input is too short.
+  (CVE-2026-70629, bsc#1274270)
+
+-------------------------------------------------------------------
+Wed Aug 14 06:52:11 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-70628.patch:
+  Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid
+  signed overflow in the capacity check.
+  (CVE-2026-70628, bsc#1274268)
+
+-------------------------------------------------------------------

New:
----
  ffmpeg-4-CVE-2026-70628.patch
  ffmpeg-4-CVE-2026-70629.patch
  ffmpeg-4-CVE-2026-70630.patch
  ffmpeg-4-CVE-2026-70631.patch
  ffmpeg-4-CVE-2026-70632.patch
  ffmpeg-4-CVE-2026-75142.patch
  ffmpeg-4-CVE-2026-75143.patch
  ffmpeg-4-CVE-2026-75144.patch
  ffmpeg-4-CVE-2026-75146.patch

----------(New B)----------
  New:
- Add ffmpeg-4-CVE-2026-70628.patch:
  Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid
  New:
- Add ffmpeg-4-CVE-2026-70629.patch:
  Backport a5fe21a1 from upstream, avcodec/rscc: do not leave
  New:
- Add ffmpeg-4-CVE-2026-70630.patch:
  Backport c22667d0 from upstream, avcodec/screenpresso: reject
  New:
- Add ffmpeg-4-CVE-2026-70631.patch:
  Backport 3c287af3 from upstream, avcodec/tiff: reject inflate
  New:
- Add ffmpeg-4-CVE-2026-70632.patch:
  Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2
  New:
- Add ffmpeg-4-CVE-2026-75142.patch:
  Backport 9d786e4b from upstream, avformat/mpegenc: reject stream
  New:
- Add ffmpeg-4-CVE-2026-75143.patch:
  Backport 1c10bcc2 from upstream, avformat/librist: honor the caller
  New:
- Add ffmpeg-4-CVE-2026-75144.patch:
  Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data
  New:
- Add ffmpeg-4-CVE-2026-75146.patch:
  Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ ffmpeg-4.spec ++++++
--- /var/tmp/diff_new_pack.L16e5r/_old  2026-09-08 16:54:40.161354966 +0200
+++ /var/tmp/diff_new_pack.L16e5r/_new  2026-09-08 16:54:40.162355008 +0200
@@ -164,6 +164,15 @@
 Patch55:        ffmpeg-4-CVE-2026-65706.patch
 Patch56:        ffmpeg-4-CVE-2026-66036-shim01.patch
 Patch57:        ffmpeg-4-CVE-2026-66036.patch
+Patch58:        ffmpeg-4-CVE-2026-70628.patch
+Patch59:        ffmpeg-4-CVE-2026-70629.patch
+Patch60:        ffmpeg-4-CVE-2026-70630.patch
+Patch61:        ffmpeg-4-CVE-2026-70631.patch
+Patch62:        ffmpeg-4-CVE-2026-70632.patch
+Patch64:        ffmpeg-4-CVE-2026-75142.patch
+Patch65:        ffmpeg-4-CVE-2026-75143.patch
+Patch66:        ffmpeg-4-CVE-2026-75144.patch
+Patch67:        ffmpeg-4-CVE-2026-75146.patch
 BuildRequires:  ladspa-devel
 BuildRequires:  libgsm-devel
 BuildRequires:  libmp3lame-devel

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.L16e5r/_old  2026-09-08 16:54:40.229357819 +0200
+++ /var/tmp/diff_new_pack.L16e5r/_new  2026-09-08 16:54:40.233357987 +0200
@@ -1,5 +1,5 @@
-mtime: 1787302634
-commit: 7d6dcca0e998a1009e33e1e77b555fbcd225c40524e161cb13901767244b56d7
+mtime: 1788692822
+commit: 8717f2501a05e13d6c46e8660428d203db26b18b57900f646e9e25d2c3761691
 url: https://src.opensuse.org/jengelh/ffmpeg-4
 revision: master
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-06 13:07:02.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ ffmpeg-4-CVE-2026-70628.patch ++++++
>From 02fc47e13f903768b75f7985a2706a6223ab4506 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:49:11 +0200
Subject: [PATCH] avcodec/dvbsub_parser: avoid signed overflow in the capacity
 check

Fixes: signed integer overflow
Fixes: out of array access
Fixes: poc.wtv
Fixes: fJeEU9JwKwsR
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 93f2a525ec6c7b467bae68322720d10188fc6e30)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/dvbsub_parser.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavcodec/dvbsub_parser.c b/libavcodec/dvbsub_parser.c
index 4527e4dd75..a93f39bfe0 100644
--- a/libavcodec/dvbsub_parser.c
+++ b/libavcodec/dvbsub_parser.c
@@ -104,7 +104,7 @@ static int dvbsub_parse(AVCodecParserContext *s,
         }
     }
 
-    if (buf_size - buf_pos + pc->packet_index > PARSE_BUF_SIZE)
+    if (buf_size - buf_pos > PARSE_BUF_SIZE - pc->packet_index)
         return buf_size;
 
 /* if not currently in a packet, pass data */
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-70629.patch ++++++
>From a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:03 +0200
Subject: [PATCH] avcodec/rscc: do not leave uninitilized data when the input
 is too short

Fixes: use of uninitialized memory
Fixes: rscc_short_deflate_heap_disclosure.avi
Fixes: plB80py3i3Bu
Found-by: Adrian Junge (vurlo)
(cherry picked from commit cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/rscc.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/libavcodec/rscc.c b/libavcodec/rscc.c
index 3715e1c6d4..5fde30ec35 100644
--- a/libavcodec/rscc.c
+++ b/libavcodec/rscc.c
@@ -311,6 +311,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
             ret = AVERROR_UNKNOWN;
             goto end;
         }
+        if (len < pixel_size) {
+            av_log(avctx, AV_LOG_WARNING, "Deflated %lu bytes, but %d are 
needed\n",
+                   len, pixel_size);
+            memset(ctx->inflated_buf + len, 0, pixel_size - len);
+            pixel_size = len;
+        }
         pixels = ctx->inflated_buf;
     }
 
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-70630.patch ++++++
>From c22667d0fd7916a33fd3e79685b7246fc48f1a62 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:41 +0200
Subject: [PATCH] avcodec/screenpresso: reject deflate output shorter than the
 frame

Fixes: use of uninitialized memory
Fixes: screenpresso_short_zlib_heap_disclosure.avi
Fixes: ksUBwBOjJodq
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 705890061467ad550ecc1dad5eea07f28ccfb43e)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/screenpresso.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c
index b27154991c..5864253d41 100644
--- a/libavcodec/screenpresso.c
+++ b/libavcodec/screenpresso.c
@@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, 
AVFrame *frame,
         return AVERROR_INVALIDDATA;
     }
 
+    /* Codec has aligned strides */
+    src_linesize = FFALIGN(avctx->width * component_size, 4);
+
     /* Inflate the frame after the 2 byte header */
     ret = uncompress(ctx->inflated_buf, &length,
                      avpkt->data + 2, avpkt->size - 2);
@@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext 
*avctx, AVFrame *frame,
         av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret);
         return AVERROR_UNKNOWN;
     }
+    if (length < src_linesize * avctx->height) {
+        av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n",
+               length, src_linesize * avctx->height);
+        return AVERROR_INVALIDDATA;
+    }
 
     ret = ff_reget_buffer(avctx, ctx->current, 0);
     if (ret < 0)
         return ret;
 
-    /* Codec has aligned strides */
-    src_linesize = FFALIGN(avctx->width * component_size, 4);
-
     /* When a keyframe is found, copy it (flipped) */
     if (keyframe)
         av_image_copy_plane(ctx->current->data[0] +
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-70631.patch ++++++
>From 3c287af3affe1286350faa69c02bcc5d49de18bb Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:44:41 +0200
Subject: [PATCH] avcodec/tiff: reject inflate output shorter than the strip

Fixes: use of uninitialized memory
Fixes: tiff_short_deflate_heap_disclosure.tiff
Fixes: 1cRIkpUVMQtn
Found-by: Adrian Junge (vurlo)
(cherry picked from commit 2f234ea34c81288e3840fca632dd16481d8de39f)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/tiff.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c
index 8a179f0fd0..b8ce7b0b55 100644
--- a/libavcodec/tiff.c
+++ b/libavcodec/tiff.c
@@ -526,6 +526,7 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
     uint8_t *zbuf;
     unsigned long outlen;
     int ret, line;
+    int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : 
lines;
     outlen = width * lines;
     zbuf   = av_malloc(outlen);
     if (!zbuf)
@@ -545,6 +546,12 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
         av_free(zbuf);
         return AVERROR_UNKNOWN;
     }
+    if (outlen < (unsigned long)width * rows) {
+        av_log(s->avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %lu are 
needed\n",
+               outlen, (unsigned long)width * rows);
+        av_free(zbuf);
+        return AVERROR_INVALIDDATA;
+    }
     src = zbuf;
     for (line = 0; line < lines; line++) {
         if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) {
@@ -592,6 +599,7 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
 {
     uint64_t outlen = width * (uint64_t)lines;
     int ret, line;
+    int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : 
lines;
     uint8_t *buf = av_malloc(outlen);
     if (!buf)
         return AVERROR(ENOMEM);
@@ -610,6 +618,12 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, 
uint8_t *dst, int stride
         av_free(buf);
         return AVERROR_UNKNOWN;
     }
+    if (outlen < (uint64_t)width * rows) {
+        av_log(s->avctx, AV_LOG_ERROR, "Uncompressed %"PRIu64" bytes, but 
%"PRIu64" are needed\n",
+               outlen, (uint64_t)width * rows);
+        av_free(buf);
+        return AVERROR_INVALIDDATA;
+    }
     src = buf;
     for (line = 0; line < lines; line++) {
         if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) {
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-70632.patch ++++++
>From 16b2049d4d5222db6cd7c031409058571c94f6a9 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Wed, 22 Jul 2026 05:53:16 +0200
Subject: [PATCH] avcodec/cfhd: reject transform-2 output wider than the plane

Fixes: out of array access
Fixes: cfhd_transform2_output_width_oob.avi
Fixes: MimvoaEVpKow
Found-by: Adrian Junge (vurlo)
(cherry picked from commit db05df9d135fb56a4babb836d5e9f5c1d984e087)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/cfhd.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/libavcodec/cfhd.c b/libavcodec/cfhd.c
index 4d430e32ef..128362ac62 100644
--- a/libavcodec/cfhd.c
+++ b/libavcodec/cfhd.c
@@ -1224,7 +1224,7 @@ finish:
 
             if (lowpass_height > s->plane[plane].band[4][1].a_height || 
lowpass_width > s->plane[plane].band[4][1].a_width ||
                 !highpass_stride || s->plane[plane].band[4][1].width > 
s->plane[plane].band[4][1].a_width ||
-                lowpass_width < 3 || lowpass_height < 3) {
+                lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > 
s->plane[plane].width) {
                 av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n");
                 ret = AVERROR(EINVAL);
                 goto end;
@@ -1345,7 +1345,7 @@ finish:
 
             if (lowpass_height > s->plane[plane].band[4][1].a_height || 
lowpass_width > s->plane[plane].band[4][1].a_width ||
                 s->plane[plane].band[4][1].width > 
s->plane[plane].band[4][1].a_width ||
-                lowpass_width < 3 || lowpass_height < 3) {
+                lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > 
s->plane[plane].width) {
                 av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n");
                 ret = AVERROR(EINVAL);
                 goto end;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-75142.patch ++++++
>From 9d786e4b5e9b8482651928574de33772aeee7be1 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/mpegenc: reject stream counts that overflow the
 system header

put_system_header() writes 12 + 3*N bytes after the pack header into a
fixed 128-byte stack buffer, but is handed a PutBitContext sized past the
real buffer, so its own bounds check never fires; ~35+ streams overflow the
stack. Reject at mux init when the system header would not fit.

Fixes: out of array access
Fixes: many.mkv
---
 libavformat/mpegenc.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/libavformat/mpegenc.c b/libavformat/mpegenc.c
index 128dfe2885..cea91d80da 100644
--- a/libavformat/mpegenc.c
+++ b/libavformat/mpegenc.c
@@ -473,6 +473,16 @@ static av_cold int mpeg_mux_init(AVFormatContext *ctx)
         if (!stream->fifo)
             return AVERROR(ENOMEM);
     }
+
+    /* The system header is emitted, right after the pack header (which is at
+     * most 14 bytes), into the fixed 128-byte buffer used by flush_packet().
+     * Reject configurations whose system header would not fit. */
+    if (get_system_header_size(ctx) > 128 - 14) {
+        av_log(ctx, AV_LOG_ERROR,
+               "Too many streams to fit the MPEG program stream system 
header\n");
+        return AVERROR(EINVAL);
+    }
+
     bitrate       = 0;
     audio_bitrate = 0;
     video_bitrate = 0;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-75143.patch ++++++
>From 1c10bcc2e17255dacb717a25ab3db142ce390602 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/librist: honor the caller buffer size in
 librist_read

librist_read() ignored its size argument and copied the full payload_len,
overflowing a smaller destination (e.g. via the async: wrapper). Clamp the
copy to the caller-provided buffer size.

Fixes: out of array access
---
 libavformat/librist.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff a/libavformat/librist.c b/libavformat/librist.c
--- a/libavformat/librist.c
+++ b/libavformat/librist.c
@@ -201,7 +201,7 @@
         return AVERROR_EXTERNAL;
     }
 
-    size = data_block->payload_len;
+    size = FFMIN(data_block->payload_len, size);
     memcpy(buf, data_block->payload, size);
     rist_receiver_data_block_free((struct rist_data_block**)&data_block);
 

++++++ ffmpeg-4-CVE-2026-75144.patch ++++++
>From 1cdeb3c4e7f1f8566d846b9b451e01c376398818 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/rtpenc_vc2hq: reject data units larger than the RTP
 payload buffer

send_packet() copied an input-derived unit/fragment size into the fixed
rtp_ctx->buf with no bound, overflowing it for a crafted Dirac unit even at
the default packet size. Reject units that do not fit in max_payload_size.

Fixes: out of array access
---
 libavformat/rtpenc_vc2hq.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index cf548191d2..3b7147dfe2 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -33,16 +33,23 @@
 #define DIRAC_PIC_NR_SIZE                    4
 #define DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT      0xEC
 
-static void send_packet(AVFormatContext *ctx, uint8_t parse_code, int 
info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m)
+static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int 
info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m)
 {
     RTPMuxContext *rtp_ctx = ctx->priv_data;
 
+    if (size < 0 ||
+        size > rtp_ctx->max_payload_size - RTP_VC2HQ_PL_HEADER_SIZE - 
info_hdr_size) {
+        av_log(ctx, AV_LOG_ERROR, "VC-2 data unit too large for RTP payload 
buffer\n");
+        return AVERROR_INVALIDDATA;
+    }
+
     AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */
     AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: 
interlaced, second field */
     AV_WB8 (&rtp_ctx->buf[3], parse_code);
     if (size > 0)
         memcpy(&rtp_ctx->buf[4 + info_hdr_size], buf, size);
     ff_rtp_send_data(ctx, rtp_ctx->buf, RTP_VC2HQ_PL_HEADER_SIZE + 
info_hdr_size + size, rtp_m);
+    return 0;
 }
 
 static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, 
int interlaced)
@@ -85,7 +92,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t 
*buf, int size, int
     AV_WB16(&info_hdr[ 6], size_scaler);
     AV_WB16(&info_hdr[ 8], frag_len);
     AV_WB16(&info_hdr[10], 0 /* nr. of slices */);
-    send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, 
interlaced, second_field, 0);
+    if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, 
interlaced, second_field, 0) < 0)
+        return AVERROR_INVALIDDATA;
     buf += frag_len;
     size -= frag_len;
 
@@ -97,7 +105,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t 
*buf, int size, int
         AV_WB16(&info_hdr[14], 0 /* slice y */);
 
         size -= frag_len;
-        send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, 
interlaced, second_field, size > 0 ? 0 : 1);
+        if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, 
frag_len, interlaced, second_field, size > 0 ? 0 : 1) < 0)
+            return AVERROR_INVALIDDATA;
         buf += frag_len;
     }
     return 0;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-75146.patch ++++++
>From 65b0dab903e5975e036b30ecc58f5935d4f151e0 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Tue, 4 Aug 2026 12:11:55 +0000
Subject: [PATCH] avformat/dashdec: reject a negative fragment index

A live manifest whose startNumber decreases across a refresh drives
cur_seq_no negative in move_segments(); get_current_fragment() only checked
the upper bound before indexing fragments[]. Add a lower-bound check and
clamp the negative delta at its source.

Fixes: out of array read
---
 libavformat/dashdec.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff a/libavformat/dashdec.c b/libavformat/dashdec.c
--- a/libavformat/dashdec.c
+++ b/libavformat/dashdec.c
@@ -1488,8 +1488,11 @@ static void move_segments(struct represe
         free_fragment_list(rep_dest);
         if (rep_src->start_number > (rep_dest->start_number + 
rep_dest->n_fragments))
             rep_dest->cur_seq_no = 0;
-        else
+        else {
             rep_dest->cur_seq_no += rep_src->start_number - 
rep_dest->start_number;
+            if (rep_dest->cur_seq_no < 0)
+                rep_dest->cur_seq_no = 0;
+        }
         rep_dest->fragments    = rep_src->fragments;
         rep_dest->n_fragments  = rep_src->n_fragments;
         rep_dest->parent  = rep_src->parent;
@@ -1608,7 +1611,7 @@ static struct fragment *get_current_frag
     DASHContext *c = pls->parent->priv_data;
 
     while (( !ff_check_interrupt(c->interrupt_callback)&& pls->n_fragments > 
0)) {
-        if (pls->cur_seq_no < pls->n_fragments) {
+        if (pls->cur_seq_no >= 0 && pls->cur_seq_no < pls->n_fragments) {
             seg_ptr = pls->fragments[pls->cur_seq_no];
             seg = av_mallocz(sizeof(struct fragment));
             if (!seg) {

Reply via email to