PR #24612 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24612
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24612.patch

Fixes: division by 0
Fixes: 4MBWdnTTajBU
Fixes: swarm-Division-by-zero-when-shape-file-has-no-non-newline-columns-059deb
Fixes: division by 0
Fixes: 4MBWdnTTajBU
Fixes: swarm-Division-by-zero-when-shape-file-has-no-non-newline-columns-059deb


>From 104134a02b011119ff06a4e29c812b580b554af5 Mon Sep 17 00:00:00 2001
From: zhang xingxing <[email protected]>
Date: Mon, 21 Sep 2026 06:14:25 +0200
Subject: [PATCH 1/3] avfilter/vf_libopencv: reject custom shape files without
 columns

Fixes: division by 0
Fixes: 4MBWdnTTajBU
Fixes: swarm-Division-by-zero-when-shape-file-has-no-non-newline-columns-059deb
---
 libavfilter/vf_libopencv.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/libavfilter/vf_libopencv.c b/libavfilter/vf_libopencv.c
index c125d294d1..e0d60c2b6d 100644
--- a/libavfilter/vf_libopencv.c
+++ b/libavfilter/vf_libopencv.c
@@ -154,6 +154,11 @@ static int read_shape_from_file(int *cols, int *rows, int 
**values, const char *
         }
         w++;
     }
+    if (*cols == 0) {
+        av_log(log_ctx, AV_LOG_ERROR, "No columns in the shape file\n");
+        ret = AVERROR_INVALIDDATA;
+        goto end;
+    }
     if (*rows > (SIZE_MAX / sizeof(int) / *cols)) {
         av_log(log_ctx, AV_LOG_ERROR, "File with size %dx%d is too big\n",
                *rows, *cols);
-- 
2.52.0


>From acb5edf280ab29006a0a2add9951f3c95c26418e Mon Sep 17 00:00:00 2001
From: zhang xingxing <[email protected]>
Date: Mon, 21 Sep 2026 06:14:25 +0200
Subject: [PATCH 2/3] avfilter/vf_libopencv: unmap the shape file on column
 overflow

Fixes: memleak
Fixes: ZbzgLVrnEIkH
Fixes: swarm-File-mapping-leak-on-column-overflow-early-return-06d09a
---
 libavfilter/vf_libopencv.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/libavfilter/vf_libopencv.c b/libavfilter/vf_libopencv.c
index e0d60c2b6d..0b333f4f4d 100644
--- a/libavfilter/vf_libopencv.c
+++ b/libavfilter/vf_libopencv.c
@@ -150,7 +150,8 @@ static int read_shape_from_file(int *cols, int *rows, int 
**values, const char *
             w = 0;
         } else if (w == INT_MAX) {
             av_log(log_ctx, AV_LOG_ERROR, "Overflow on the number of columns 
in the file\n");
-            return AVERROR_INVALIDDATA;
+            ret = AVERROR_INVALIDDATA;
+            goto end;
         }
         w++;
     }
-- 
2.52.0


>From 5188334e08244dc3f79a26be036cd1b71d39e1e1 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Mon, 21 Sep 2026 06:14:25 +0200
Subject: [PATCH 3/3] avfilter/vf_libopencv: return the error from
 read_shape_from_file()

Found during triage/review of the security reports 4MBWdnTTajBU and
ZbzgLVrnEIkH.
---
 libavfilter/vf_libopencv.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/libavfilter/vf_libopencv.c b/libavfilter/vf_libopencv.c
index 0b333f4f4d..b8366a00c7 100644
--- a/libavfilter/vf_libopencv.c
+++ b/libavfilter/vf_libopencv.c
@@ -186,6 +186,8 @@ static int read_shape_from_file(int *cols, int *rows, int 
**values, const char *
 
 end:
     av_file_unmap(buf, size);
+    if (ret < 0)
+        return ret;
 
 #ifdef DEBUG
     {
-- 
2.52.0

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to