This is an automated email from the git hooks/post-receive script.

Git pushed a commit to branch master
in repository ffmpeg.

commit ed27bfcbbbc0872c0195eaf4dd2c0c93b9f1778e
Author:     Joshua Rogers <[email protected]>
AuthorDate: Mon Aug 31 15:31:50 2026 +0200
Commit:     michaelni <[email protected]>
CommitDate: Sat Oct 3 21:50:18 2026 +0000

    avutil/avstring: fix infinite loop in av_strireplace with empty search 
string
    
    av_stristr() returns the input pointer unchanged for an empty needle,
    so an empty 'from' argument left pstr never advancing and caused
    av_strireplace() to loop forever (and grow the buffer unboundedly if
    'to' was non-empty). Return a duplicate of 'str' when 'from' is empty.
    
    Fixes: Timeout
    Fixes: q8954W25MJoa
    Fixes: AISLE-2026-0100-00001
    Found-by: Joshua Rogers <[email protected]>
    Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavutil/avstring.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/libavutil/avstring.c b/libavutil/avstring.c
index 1487297cba..9b81da33bf 100644
--- a/libavutil/avstring.c
+++ b/libavutil/avstring.c
@@ -234,6 +234,9 @@ char *av_strireplace(const char *str, const char *from, 
const char *to)
     size_t tolen = strlen(to), fromlen = strlen(from);
     AVBPrint pbuf;
 
+    if (!fromlen)
+        return av_strdup(str);
+
     av_bprint_init(&pbuf, 1, AV_BPRINT_SIZE_UNLIMITED);
     while ((pstr2 = av_stristr(pstr, from))) {
         av_bprint_append_data(&pbuf, pstr, pstr2 - pstr);

-- 
To stop receiving notification emails like this one, please contact
[email protected].
_______________________________________________
ffmpeg-cvslog mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to