Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package ffmpeg-4 for openSUSE:Factory checked in at 2026-09-08 16:53:46 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/ffmpeg-4 (Old) and /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "ffmpeg-4" Tue Sep 8 16:53:46 2026 rev:100 rq:1376009 version:4.4.8 Changes: -------- --- /work/SRC/openSUSE:Factory/ffmpeg-4/ffmpeg-4.changes 2026-08-21 17:02:44.837081543 +0200 +++ /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1265/ffmpeg-4.changes 2026-09-08 16:54:38.885301431 +0200 @@ -1,0 +2,72 @@ +Mon Aug 28 04:47:54 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-75146.patch: + Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative + fragment index. + (CVE-2026-75146, bsc#1276412) + +------------------------------------------------------------------- +Mon Aug 28 03:34:50 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-75144.patch: + Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data + units larger than the RTP payload buffer. + (CVE-2026-75144, bsc#1276410) + +------------------------------------------------------------------- +Mon Aug 28 03:17:21 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-75143.patch: + Backport 1c10bcc2 from upstream, avformat/librist: honor the caller + buffer size in librist_read. + (CVE-2026-75143, bsc#1276409) + +------------------------------------------------------------------- +Mon Aug 28 02:58:12 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-75142.patch: + Backport 9d786e4b from upstream, avformat/mpegenc: reject stream + counts that overflow the system header. + (CVE-2026-75142, bsc#1276408) + +------------------------------------------------------------------- +Wed Aug 14 09:44:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-70632.patch: + Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 + output wider than the plane. + (CVE-2026-70632, bsc#1274289) + +------------------------------------------------------------------- +Wed Aug 14 08:27:41 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-70631.patch: + Backport 3c287af3 from upstream, avcodec/tiff: reject inflate + output shorter than the strip. + (CVE-2026-70631, bsc#1274287) + +------------------------------------------------------------------- +Wed Aug 14 07:58:24 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-70630.patch: + Backport c22667d0 from upstream, avcodec/screenpresso: reject + deflate output shorter than the frame. + (CVE-2026-70630, bsc#1274282) + +------------------------------------------------------------------- +Wed Aug 14 07:22:18 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-70629.patch: + Backport a5fe21a1 from upstream, avcodec/rscc: do not leave + uninitilized data when the input is too short. + (CVE-2026-70629, bsc#1274270) + +------------------------------------------------------------------- +Wed Aug 14 06:52:11 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-70628.patch: + Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid + signed overflow in the capacity check. + (CVE-2026-70628, bsc#1274268) + +------------------------------------------------------------------- New: ---- ffmpeg-4-CVE-2026-70628.patch ffmpeg-4-CVE-2026-70629.patch ffmpeg-4-CVE-2026-70630.patch ffmpeg-4-CVE-2026-70631.patch ffmpeg-4-CVE-2026-70632.patch ffmpeg-4-CVE-2026-75142.patch ffmpeg-4-CVE-2026-75143.patch ffmpeg-4-CVE-2026-75144.patch ffmpeg-4-CVE-2026-75146.patch ----------(New B)---------- New: - Add ffmpeg-4-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid New: - Add ffmpeg-4-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave New: - Add ffmpeg-4-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject New: - Add ffmpeg-4-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate New: - Add ffmpeg-4-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 New: - Add ffmpeg-4-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream New: - Add ffmpeg-4-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller New: - Add ffmpeg-4-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data New: - Add ffmpeg-4-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ ffmpeg-4.spec ++++++ --- /var/tmp/diff_new_pack.L16e5r/_old 2026-09-08 16:54:40.161354966 +0200 +++ /var/tmp/diff_new_pack.L16e5r/_new 2026-09-08 16:54:40.162355008 +0200 @@ -164,6 +164,15 @@ Patch55: ffmpeg-4-CVE-2026-65706.patch Patch56: ffmpeg-4-CVE-2026-66036-shim01.patch Patch57: ffmpeg-4-CVE-2026-66036.patch +Patch58: ffmpeg-4-CVE-2026-70628.patch +Patch59: ffmpeg-4-CVE-2026-70629.patch +Patch60: ffmpeg-4-CVE-2026-70630.patch +Patch61: ffmpeg-4-CVE-2026-70631.patch +Patch62: ffmpeg-4-CVE-2026-70632.patch +Patch64: ffmpeg-4-CVE-2026-75142.patch +Patch65: ffmpeg-4-CVE-2026-75143.patch +Patch66: ffmpeg-4-CVE-2026-75144.patch +Patch67: ffmpeg-4-CVE-2026-75146.patch BuildRequires: ladspa-devel BuildRequires: libgsm-devel BuildRequires: libmp3lame-devel ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.L16e5r/_old 2026-09-08 16:54:40.229357819 +0200 +++ /var/tmp/diff_new_pack.L16e5r/_new 2026-09-08 16:54:40.233357987 +0200 @@ -1,5 +1,5 @@ -mtime: 1787302634 -commit: 7d6dcca0e998a1009e33e1e77b555fbcd225c40524e161cb13901767244b56d7 +mtime: 1788692822 +commit: 8717f2501a05e13d6c46e8660428d203db26b18b57900f646e9e25d2c3761691 url: https://src.opensuse.org/jengelh/ffmpeg-4 revision: master ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-06 13:07:02.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ ffmpeg-4-CVE-2026-70628.patch ++++++ >From 02fc47e13f903768b75f7985a2706a6223ab4506 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:49:11 +0200 Subject: [PATCH] avcodec/dvbsub_parser: avoid signed overflow in the capacity check Fixes: signed integer overflow Fixes: out of array access Fixes: poc.wtv Fixes: fJeEU9JwKwsR Found-by: Adrian Junge (vurlo) (cherry picked from commit 93f2a525ec6c7b467bae68322720d10188fc6e30) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/dvbsub_parser.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/dvbsub_parser.c b/libavcodec/dvbsub_parser.c index 4527e4dd75..a93f39bfe0 100644 --- a/libavcodec/dvbsub_parser.c +++ b/libavcodec/dvbsub_parser.c @@ -104,7 +104,7 @@ static int dvbsub_parse(AVCodecParserContext *s, } } - if (buf_size - buf_pos + pc->packet_index > PARSE_BUF_SIZE) + if (buf_size - buf_pos > PARSE_BUF_SIZE - pc->packet_index) return buf_size; /* if not currently in a packet, pass data */ -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-70629.patch ++++++ >From a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:03 +0200 Subject: [PATCH] avcodec/rscc: do not leave uninitilized data when the input is too short Fixes: use of uninitialized memory Fixes: rscc_short_deflate_heap_disclosure.avi Fixes: plB80py3i3Bu Found-by: Adrian Junge (vurlo) (cherry picked from commit cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rscc.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/libavcodec/rscc.c b/libavcodec/rscc.c index 3715e1c6d4..5fde30ec35 100644 --- a/libavcodec/rscc.c +++ b/libavcodec/rscc.c @@ -311,6 +311,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, AVFrame *frame, ret = AVERROR_UNKNOWN; goto end; } + if (len < pixel_size) { + av_log(avctx, AV_LOG_WARNING, "Deflated %lu bytes, but %d are needed\n", + len, pixel_size); + memset(ctx->inflated_buf + len, 0, pixel_size - len); + pixel_size = len; + } pixels = ctx->inflated_buf; } -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-70630.patch ++++++ >From c22667d0fd7916a33fd3e79685b7246fc48f1a62 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:41 +0200 Subject: [PATCH] avcodec/screenpresso: reject deflate output shorter than the frame Fixes: use of uninitialized memory Fixes: screenpresso_short_zlib_heap_disclosure.avi Fixes: ksUBwBOjJodq Found-by: Adrian Junge (vurlo) (cherry picked from commit 705890061467ad550ecc1dad5eea07f28ccfb43e) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/screenpresso.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c index b27154991c..5864253d41 100644 --- a/libavcodec/screenpresso.c +++ b/libavcodec/screenpresso.c @@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame, return AVERROR_INVALIDDATA; } + /* Codec has aligned strides */ + src_linesize = FFALIGN(avctx->width * component_size, 4); + /* Inflate the frame after the 2 byte header */ ret = uncompress(ctx->inflated_buf, &length, avpkt->data + 2, avpkt->size - 2); @@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame, av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret); return AVERROR_UNKNOWN; } + if (length < src_linesize * avctx->height) { + av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n", + length, src_linesize * avctx->height); + return AVERROR_INVALIDDATA; + } ret = ff_reget_buffer(avctx, ctx->current, 0); if (ret < 0) return ret; - /* Codec has aligned strides */ - src_linesize = FFALIGN(avctx->width * component_size, 4); - /* When a keyframe is found, copy it (flipped) */ if (keyframe) av_image_copy_plane(ctx->current->data[0] + -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-70631.patch ++++++ >From 3c287af3affe1286350faa69c02bcc5d49de18bb Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:44:41 +0200 Subject: [PATCH] avcodec/tiff: reject inflate output shorter than the strip Fixes: use of uninitialized memory Fixes: tiff_short_deflate_heap_disclosure.tiff Fixes: 1cRIkpUVMQtn Found-by: Adrian Junge (vurlo) (cherry picked from commit 2f234ea34c81288e3840fca632dd16481d8de39f) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/tiff.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c index 8a179f0fd0..b8ce7b0b55 100644 --- a/libavcodec/tiff.c +++ b/libavcodec/tiff.c @@ -526,6 +526,7 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, uint8_t *dst, int stride uint8_t *zbuf; unsigned long outlen; int ret, line; + int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : lines; outlen = width * lines; zbuf = av_malloc(outlen); if (!zbuf) @@ -545,6 +546,12 @@ static int tiff_unpack_zlib(TiffContext *s, AVFrame *p, uint8_t *dst, int stride av_free(zbuf); return AVERROR_UNKNOWN; } + if (outlen < (unsigned long)width * rows) { + av_log(s->avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %lu are needed\n", + outlen, (unsigned long)width * rows); + av_free(zbuf); + return AVERROR_INVALIDDATA; + } src = zbuf; for (line = 0; line < lines; line++) { if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) { @@ -592,6 +599,7 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, uint8_t *dst, int stride { uint64_t outlen = width * (uint64_t)lines; int ret, line; + int rows = is_yuv ? (lines + s->subsampling[1] - 1) / s->subsampling[1] : lines; uint8_t *buf = av_malloc(outlen); if (!buf) return AVERROR(ENOMEM); @@ -610,6 +618,12 @@ static int tiff_unpack_lzma(TiffContext *s, AVFrame *p, uint8_t *dst, int stride av_free(buf); return AVERROR_UNKNOWN; } + if (outlen < (uint64_t)width * rows) { + av_log(s->avctx, AV_LOG_ERROR, "Uncompressed %"PRIu64" bytes, but %"PRIu64" are needed\n", + outlen, (uint64_t)width * rows); + av_free(buf); + return AVERROR_INVALIDDATA; + } src = buf; for (line = 0; line < lines; line++) { if (s->bpp < 8 && s->avctx->pix_fmt == AV_PIX_FMT_PAL8) { -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-70632.patch ++++++ >From 16b2049d4d5222db6cd7c031409058571c94f6a9 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Wed, 22 Jul 2026 05:53:16 +0200 Subject: [PATCH] avcodec/cfhd: reject transform-2 output wider than the plane Fixes: out of array access Fixes: cfhd_transform2_output_width_oob.avi Fixes: MimvoaEVpKow Found-by: Adrian Junge (vurlo) (cherry picked from commit db05df9d135fb56a4babb836d5e9f5c1d984e087) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/cfhd.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/libavcodec/cfhd.c b/libavcodec/cfhd.c index 4d430e32ef..128362ac62 100644 --- a/libavcodec/cfhd.c +++ b/libavcodec/cfhd.c @@ -1224,7 +1224,7 @@ finish: if (lowpass_height > s->plane[plane].band[4][1].a_height || lowpass_width > s->plane[plane].band[4][1].a_width || !highpass_stride || s->plane[plane].band[4][1].width > s->plane[plane].band[4][1].a_width || - lowpass_width < 3 || lowpass_height < 3) { + lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > s->plane[plane].width) { av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n"); ret = AVERROR(EINVAL); goto end; @@ -1345,7 +1345,7 @@ finish: if (lowpass_height > s->plane[plane].band[4][1].a_height || lowpass_width > s->plane[plane].band[4][1].a_width || s->plane[plane].band[4][1].width > s->plane[plane].band[4][1].a_width || - lowpass_width < 3 || lowpass_height < 3) { + lowpass_width < 3 || lowpass_height < 3 || lowpass_width * 2 > s->plane[plane].width) { av_log(avctx, AV_LOG_ERROR, "Invalid plane dimensions\n"); ret = AVERROR(EINVAL); goto end; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-75142.patch ++++++ >From 9d786e4b5e9b8482651928574de33772aeee7be1 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/mpegenc: reject stream counts that overflow the system header put_system_header() writes 12 + 3*N bytes after the pack header into a fixed 128-byte stack buffer, but is handed a PutBitContext sized past the real buffer, so its own bounds check never fires; ~35+ streams overflow the stack. Reject at mux init when the system header would not fit. Fixes: out of array access Fixes: many.mkv --- libavformat/mpegenc.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/libavformat/mpegenc.c b/libavformat/mpegenc.c index 128dfe2885..cea91d80da 100644 --- a/libavformat/mpegenc.c +++ b/libavformat/mpegenc.c @@ -473,6 +473,16 @@ static av_cold int mpeg_mux_init(AVFormatContext *ctx) if (!stream->fifo) return AVERROR(ENOMEM); } + + /* The system header is emitted, right after the pack header (which is at + * most 14 bytes), into the fixed 128-byte buffer used by flush_packet(). + * Reject configurations whose system header would not fit. */ + if (get_system_header_size(ctx) > 128 - 14) { + av_log(ctx, AV_LOG_ERROR, + "Too many streams to fit the MPEG program stream system header\n"); + return AVERROR(EINVAL); + } + bitrate = 0; audio_bitrate = 0; video_bitrate = 0; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-75143.patch ++++++ >From 1c10bcc2e17255dacb717a25ab3db142ce390602 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/librist: honor the caller buffer size in librist_read librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination (e.g. via the async: wrapper). Clamp the copy to the caller-provided buffer size. Fixes: out of array access --- libavformat/librist.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff a/libavformat/librist.c b/libavformat/librist.c --- a/libavformat/librist.c +++ b/libavformat/librist.c @@ -201,7 +201,7 @@ return AVERROR_EXTERNAL; } - size = data_block->payload_len; + size = FFMIN(data_block->payload_len, size); memcpy(buf, data_block->payload, size); rist_receiver_data_block_free((struct rist_data_block**)&data_block); ++++++ ffmpeg-4-CVE-2026-75144.patch ++++++ >From 1cdeb3c4e7f1f8566d846b9b451e01c376398818 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer send_packet() copied an input-derived unit/fragment size into the fixed rtp_ctx->buf with no bound, overflowing it for a crafted Dirac unit even at the default packet size. Reject units that do not fit in max_payload_size. Fixes: out of array access --- libavformat/rtpenc_vc2hq.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c index cf548191d2..3b7147dfe2 100644 --- a/libavformat/rtpenc_vc2hq.c +++ b/libavformat/rtpenc_vc2hq.c @@ -33,16 +33,23 @@ #define DIRAC_PIC_NR_SIZE 4 #define DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT 0xEC -static void send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m) +static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_size, const uint8_t *buf, int size, int i, int f, int rtp_m) { RTPMuxContext *rtp_ctx = ctx->priv_data; + if (size < 0 || + size > rtp_ctx->max_payload_size - RTP_VC2HQ_PL_HEADER_SIZE - info_hdr_size) { + av_log(ctx, AV_LOG_ERROR, "VC-2 data unit too large for RTP payload buffer\n"); + return AVERROR_INVALIDDATA; + } + AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */ AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: interlaced, second field */ AV_WB8 (&rtp_ctx->buf[3], parse_code); if (size > 0) memcpy(&rtp_ctx->buf[4 + info_hdr_size], buf, size); ff_rtp_send_data(ctx, rtp_ctx->buf, RTP_VC2HQ_PL_HEADER_SIZE + info_hdr_size + size, rtp_m); + return 0; } static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int interlaced) @@ -85,7 +92,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int AV_WB16(&info_hdr[ 6], size_scaler); AV_WB16(&info_hdr[ 8], frag_len); AV_WB16(&info_hdr[10], 0 /* nr. of slices */); - send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, interlaced, second_field, 0); + if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 12, buf, frag_len, interlaced, second_field, 0) < 0) + return AVERROR_INVALIDDATA; buf += frag_len; size -= frag_len; @@ -97,7 +105,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int AV_WB16(&info_hdr[14], 0 /* slice y */); size -= frag_len; - send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, interlaced, second_field, size > 0 ? 0 : 1); + if (send_packet(ctx, DIRAC_RTP_PCODE_HQ_PIC_FRAGMENT, 16, buf, frag_len, interlaced, second_field, size > 0 ? 0 : 1) < 0) + return AVERROR_INVALIDDATA; buf += frag_len; } return 0; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-75146.patch ++++++ >From 65b0dab903e5975e036b30ecc58f5935d4f151e0 Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Tue, 4 Aug 2026 12:11:55 +0000 Subject: [PATCH] avformat/dashdec: reject a negative fragment index A live manifest whose startNumber decreases across a refresh drives cur_seq_no negative in move_segments(); get_current_fragment() only checked the upper bound before indexing fragments[]. Add a lower-bound check and clamp the negative delta at its source. Fixes: out of array read --- libavformat/dashdec.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff a/libavformat/dashdec.c b/libavformat/dashdec.c --- a/libavformat/dashdec.c +++ b/libavformat/dashdec.c @@ -1488,8 +1488,11 @@ static void move_segments(struct represe free_fragment_list(rep_dest); if (rep_src->start_number > (rep_dest->start_number + rep_dest->n_fragments)) rep_dest->cur_seq_no = 0; - else + else { rep_dest->cur_seq_no += rep_src->start_number - rep_dest->start_number; + if (rep_dest->cur_seq_no < 0) + rep_dest->cur_seq_no = 0; + } rep_dest->fragments = rep_src->fragments; rep_dest->n_fragments = rep_src->n_fragments; rep_dest->parent = rep_src->parent; @@ -1608,7 +1611,7 @@ static struct fragment *get_current_frag DASHContext *c = pls->parent->priv_data; while (( !ff_check_interrupt(c->interrupt_callback)&& pls->n_fragments > 0)) { - if (pls->cur_seq_no < pls->n_fragments) { + if (pls->cur_seq_no >= 0 && pls->cur_seq_no < pls->n_fragments) { seg_ptr = pls->fragments[pls->cur_seq_no]; seg = av_mallocz(sizeof(struct fragment)); if (!seg) {
