PR #24612 opened by michaelni URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24612 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24612.patch
Fixes: division by 0 Fixes: 4MBWdnTTajBU Fixes: swarm-Division-by-zero-when-shape-file-has-no-non-newline-columns-059deb Fixes: division by 0 Fixes: 4MBWdnTTajBU Fixes: swarm-Division-by-zero-when-shape-file-has-no-non-newline-columns-059deb >From 104134a02b011119ff06a4e29c812b580b554af5 Mon Sep 17 00:00:00 2001 From: zhang xingxing <[email protected]> Date: Mon, 21 Sep 2026 06:14:25 +0200 Subject: [PATCH 1/3] avfilter/vf_libopencv: reject custom shape files without columns Fixes: division by 0 Fixes: 4MBWdnTTajBU Fixes: swarm-Division-by-zero-when-shape-file-has-no-non-newline-columns-059deb --- libavfilter/vf_libopencv.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/libavfilter/vf_libopencv.c b/libavfilter/vf_libopencv.c index c125d294d1..e0d60c2b6d 100644 --- a/libavfilter/vf_libopencv.c +++ b/libavfilter/vf_libopencv.c @@ -154,6 +154,11 @@ static int read_shape_from_file(int *cols, int *rows, int **values, const char * } w++; } + if (*cols == 0) { + av_log(log_ctx, AV_LOG_ERROR, "No columns in the shape file\n"); + ret = AVERROR_INVALIDDATA; + goto end; + } if (*rows > (SIZE_MAX / sizeof(int) / *cols)) { av_log(log_ctx, AV_LOG_ERROR, "File with size %dx%d is too big\n", *rows, *cols); -- 2.52.0 >From acb5edf280ab29006a0a2add9951f3c95c26418e Mon Sep 17 00:00:00 2001 From: zhang xingxing <[email protected]> Date: Mon, 21 Sep 2026 06:14:25 +0200 Subject: [PATCH 2/3] avfilter/vf_libopencv: unmap the shape file on column overflow Fixes: memleak Fixes: ZbzgLVrnEIkH Fixes: swarm-File-mapping-leak-on-column-overflow-early-return-06d09a --- libavfilter/vf_libopencv.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/libavfilter/vf_libopencv.c b/libavfilter/vf_libopencv.c index e0d60c2b6d..0b333f4f4d 100644 --- a/libavfilter/vf_libopencv.c +++ b/libavfilter/vf_libopencv.c @@ -150,7 +150,8 @@ static int read_shape_from_file(int *cols, int *rows, int **values, const char * w = 0; } else if (w == INT_MAX) { av_log(log_ctx, AV_LOG_ERROR, "Overflow on the number of columns in the file\n"); - return AVERROR_INVALIDDATA; + ret = AVERROR_INVALIDDATA; + goto end; } w++; } -- 2.52.0 >From 5188334e08244dc3f79a26be036cd1b71d39e1e1 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Mon, 21 Sep 2026 06:14:25 +0200 Subject: [PATCH 3/3] avfilter/vf_libopencv: return the error from read_shape_from_file() Found during triage/review of the security reports 4MBWdnTTajBU and ZbzgLVrnEIkH. --- libavfilter/vf_libopencv.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libavfilter/vf_libopencv.c b/libavfilter/vf_libopencv.c index 0b333f4f4d..b8366a00c7 100644 --- a/libavfilter/vf_libopencv.c +++ b/libavfilter/vf_libopencv.c @@ -186,6 +186,8 @@ static int read_shape_from_file(int *cols, int *rows, int **values, const char * end: av_file_unmap(buf, size); + if (ret < 0) + return ret; #ifdef DEBUG { -- 2.52.0 _______________________________________________ ffmpeg-devel mailing list -- [email protected] To unsubscribe send an email to [email protected]
