PR #24607 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24607
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24607.patch

Fixes: endless HTTP request loop, ffmpeg never terminates
Fixes: dDqntqRxpBRI
Regression since: bf1722a9c6a6fcfeb7c35a47a3a1f4530402dcba
Found-by: OpenSec <[email protected]>



>From 899cc38d54a6f57f2599c39782ecdac9fc00f28c Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Mon, 21 Sep 2026 05:29:44 +0200
Subject: [PATCH] avformat/http: reject a Content-Range whose end lies before
 its start

Fixes: endless HTTP request loop, ffmpeg never terminates
Fixes: dDqntqRxpBRI
Regression since: bf1722a9c6a6fcfeb7c35a47a3a1f4530402dcba
Found-by: OpenSec <[email protected]>
---
 libavformat/http.c | 14 +++++++++++---
 1 file changed, 11 insertions(+), 3 deletions(-)

diff --git a/libavformat/http.c b/libavformat/http.c
index 686aa6b7b2..b72fee82c8 100644
--- a/libavformat/http.c
+++ b/libavformat/http.c
@@ -968,7 +968,7 @@ static int parse_location(HTTPContext *s, const char *p)
 }
 
 /* "bytes $from-$to/$document_size" */
-static void parse_content_range(URLContext *h, const char *p)
+static int parse_content_range(URLContext *h, const char *p)
 {
     HTTPContext *s = h->priv_data;
     const char *slash, *end;
@@ -976,13 +976,20 @@ static void parse_content_range(URLContext *h, const char 
*p)
     if (!strncmp(p, "bytes ", 6)) {
         p     += 6;
         s->off = strtoull(p, NULL, 10);
-        if ((end = strchr(p, '-')) && strlen(end) > 0)
+        if ((end = strchr(p, '-')) && strlen(end) > 0) {
             s->range_end = strtoull(end + 1, NULL, 10) + 1;
+            if (s->range_end <= s->off) {
+                av_log(h, AV_LOG_ERROR, "Invalid Content-Range: end %"PRIu64" 
before start %"PRIu64"\n",
+                       s->range_end - 1, s->off);
+                return AVERROR_INVALIDDATA;
+            }
+        }
         if ((slash = strchr(p, '/')) && strlen(slash) > 0)
             s->filesize_from_content_range = strtoull(slash + 1, NULL, 10);
     }
     if (s->seekable == -1 && (!s->is_akamai || s->filesize != 2147483647))
         h->is_streamed = 0; /* we _can_ in fact seek */
+    return 0;
 }
 
 static int parse_content_encoding(URLContext *h, const char *p)
@@ -1366,7 +1373,8 @@ static int process_line(URLContext *h, char *line, int 
line_count, int *parsed_h
                    s->filesize == UINT64_MAX) {
             s->filesize = strtoull(p, NULL, 10);
         } else if (!av_strcasecmp(tag, "Content-Range")) {
-            parse_content_range(h, p);
+            if ((ret = parse_content_range(h, p)) < 0)
+                return ret;
         } else if (!av_strcasecmp(tag, "Accept-Ranges") &&
                    !strncmp(p, "bytes", 5) &&
                    s->seekable == -1) {
-- 
2.52.0

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to