PR #24595 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24595
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24595.patch

The per-plane copy loop only checked src->linesize[i] for zero, not for
negative values. AVFrame linesizes can be negative for vertically-flipped
frames, but CUDA_MEMCPY2D's pitch/width fields expect non-negative sizes,
so a negative linesize was reinterpreted as a huge unsigned value.

Jump to the existing fail: label rather than exit: directly, since an
earlier plane's copy may already be queued on the stream (copy_queued),
and fail: syncs the stream before returning on error.

Fixes: ogLupSp7oZ6D
Found-by: Joshua Rogers <[email protected]>

I failed to replicate a out of bound access



>From 212ffa0e846acda2aaf6e4856cf0bebfc0c172b4 Mon Sep 17 00:00:00 2001
From: Joshua Rogers <[email protected]>
Date: Mon, 31 Aug 2026 15:31:38 +0200
Subject: [PATCH] avutil/hwcontext_cuda: reject negative linesizes in CUDA
 frame transfer

The per-plane copy loop only checked src->linesize[i] for zero, not for
negative values. AVFrame linesizes can be negative for vertically-flipped
frames, but CUDA_MEMCPY2D's pitch/width fields expect non-negative sizes,
so a negative linesize was reinterpreted as a huge unsigned value.

Jump to the existing fail: label rather than exit: directly, since an
earlier plane's copy may already be queued on the stream (copy_queued),
and fail: syncs the stream before returning on error.

Fixes: ogLupSp7oZ6D
Found-by: Joshua Rogers <[email protected]>

I failed to replicate a out of bound access
---
 libavutil/hwcontext_cuda.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/libavutil/hwcontext_cuda.c b/libavutil/hwcontext_cuda.c
index 0ee6bb4945..0f38907eea 100644
--- a/libavutil/hwcontext_cuda.c
+++ b/libavutil/hwcontext_cuda.c
@@ -567,6 +567,11 @@ static int cuda_transfer_data(AVHWFramesContext *ctx, 
AVFrame *dst,
         int src_is_nonplanar_cuarray = 0;
         int dst_is_nonplanar_cuarray = 0;
 
+        if (src->linesize[i] < 0 || dst->linesize[i] < 0) {
+            ret = AVERROR(EINVAL);
+            goto fail;
+        }
+
         CUDA_MEMCPY2D cpy = {
             .srcPitch      = src->linesize[i],
             .dstPitch      = dst->linesize[i],
-- 
2.52.0

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to