PR #24592 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592.patch

Fixes: Timeout
Fixes: q8954W25MJoa
Fixes: AISLE-2026-0100-00001
Found-by: Joshua Rogers <[email protected]>
Signed-off-by: Michael Niedermayer <[email protected]>


>From 59596b08f9c8118c7f275023a631895a7edcd79c Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Mon, 31 Aug 2026 15:31:50 +0200
Subject: [PATCH 1/2] avutil/avstring: fix infinite loop in av_strireplace with
 empty search string

av_stristr() returns the input pointer unchanged for an empty needle,
so an empty 'from' argument left pstr never advancing and caused
av_strireplace() to loop forever (and grow the buffer unboundedly if
'to' was non-empty). Return a duplicate of 'str' when 'from' is empty.

Fixes: Timeout
Fixes: q8954W25MJoa
Fixes: AISLE-2026-0100-00001
Found-by: Joshua Rogers <[email protected]>
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavutil/avstring.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/libavutil/avstring.c b/libavutil/avstring.c
index 1487297cba..9b81da33bf 100644
--- a/libavutil/avstring.c
+++ b/libavutil/avstring.c
@@ -234,6 +234,9 @@ char *av_strireplace(const char *str, const char *from, 
const char *to)
     size_t tolen = strlen(to), fromlen = strlen(from);
     AVBPrint pbuf;
 
+    if (!fromlen)
+        return av_strdup(str);
+
     av_bprint_init(&pbuf, 1, AV_BPRINT_SIZE_UNLIMITED);
     while ((pstr2 = av_stristr(pstr, from))) {
         av_bprint_append_data(&pbuf, pstr, pstr2 - pstr);
-- 
2.52.0


>From 5fab0973c272cf422204669ffe7fe051d1b627fd Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 20 Sep 2026 00:04:04 +0200
Subject: [PATCH 2/2] avformat/dashdec: return EOF when a byte-range segment is
 exhausted

Fixes: Timeout
Fixes: t593bxSA0XOy
Found during triage/review of the security report q8954W25MJoa
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/dashdec.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/libavformat/dashdec.c b/libavformat/dashdec.c
index 740ac6bc1c..7230b6a6d6 100644
--- a/libavformat/dashdec.c
+++ b/libavformat/dashdec.c
@@ -1747,8 +1747,11 @@ static int read_from_url(struct representation *pls, 
struct fragment *seg,
     int ret;
 
     /* limit read if the fragment was only a part of a file */
-    if (seg->size >= 0)
+    if (seg->size >= 0) {
         buf_size = FFMIN(buf_size, pls->cur_seg_size - pls->cur_seg_offset);
+        if (buf_size <= 0)
+            return AVERROR_EOF;
+    }
 
     ret = avio_read(pls->input, buf, buf_size);
     if (ret > 0)
-- 
2.52.0

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to