This is an automated email from the git hooks/post-receive script.
Git pushed a commit to branch master
in repository ffmpeg.
The following commit(s) were added to refs/heads/master by this push:
new d3ad8a7fee avformat/rawutils: reject raw RGB frames that do not fit an
AVPacket
d3ad8a7fee is described below
commit d3ad8a7fee6a647c6362e4a105d949282d50a98f
Author: Michael Niedermayer <[email protected]>
AuthorDate: Wed Jul 22 05:57:51 2026 +0200
Commit: Michael Niedermayer <[email protected]>
CommitDate: Mon Aug 3 13:51:52 2026 +0200
avformat/rawutils: reject raw RGB frames that do not fit an AVPacket
Fixes: integer overflow
Fixes: out of array access
Fixes: payload.film
Fixes: czK1F83k3zvT
Found-by: Clouditera Security, Z.ai Security, NSFOCUS
---
libavformat/rawutils.c | 20 +++++++++++++-------
1 file changed, 13 insertions(+), 7 deletions(-)
diff --git a/libavformat/rawutils.c b/libavformat/rawutils.c
index e44c946d47..bf5113555f 100644
--- a/libavformat/rawutils.c
+++ b/libavformat/rawutils.c
@@ -29,15 +29,21 @@ int ff_reshuffle_raw_rgb(AVFormatContext *s, AVPacket
**ppkt, AVCodecParameters
int ret;
AVPacket *pkt = *ppkt;
int64_t bpc = par->bits_per_coded_sample != 15 ?
par->bits_per_coded_sample : 16;
- int min_stride = (par->width * bpc + 7) >> 3;
- int with_pal_size = min_stride * par->height + 1024;
- int contains_pal = bpc == 8 && pkt->size == with_pal_size;
- int size = contains_pal ? min_stride * par->height : pkt->size;
- int stride = size / par->height;
- int padding = expected_stride - FFMIN(expected_stride, stride);
- int y;
+ int64_t min_stride = (par->width * bpc + 7) >> 3;
+ int with_pal_size, contains_pal, size, stride, padding, y;
AVPacket *new_pkt;
+ if (par->height <= 0 || min_stride <= 0 || expected_stride <= 0 ||
+ min_stride > (INT_MAX - 1024) / par->height ||
+ expected_stride > (INT_MAX - AV_INPUT_BUFFER_PADDING_SIZE) /
par->height)
+ return AVERROR(EINVAL);
+
+ with_pal_size = min_stride * par->height + 1024;
+ contains_pal = bpc == 8 && pkt->size == with_pal_size;
+ size = contains_pal ? min_stride * par->height : pkt->size;
+ stride = size / par->height;
+ padding = expected_stride - FFMIN(expected_stride, stride);
+
if (pkt->size == expected_stride * par->height)
return 0;
if (size != stride * par->height)
_______________________________________________
ffmpeg-cvslog mailing list -- [email protected]
To unsubscribe send an email to [email protected]