Hi Yoann,

Any update on this


Thanks,

Bhavesh Maheshwari
Engineer
+91 8827543501
[email protected]<mailto:[email protected]>
[cid:d3773a93-eb5a-4d0d-a651-42fd8103d1c8]<https://www.einfochips.com/>
________________________________
From: Bhavesh Rajesh Maheshwari <[email protected]>
Sent: 28 September 2026 15:48
To: [email protected] 
<[email protected]>; [email protected] 
<[email protected]>
Subject: Re: [External] Re: [wrynose][oe-core][PATCH 5/5] ffmpeg: Fix for 
CVE-2026-66041

Hi Yoann,
Thanks for checking. I looked at the FFmpeg 8.0 QuircContext documentation and 
source. Although Doxygen lists the struct, it is defined in 
libavfilter/vf_quirc.c and used as the quirc filter’s private context. It isn’t 
part of the public API.
The patch adds width and height fields to that private context, and the build 
with the patch applied is verified. I don’t expect this to break supported 
external code. The only potential concern would be downstream code relying 
directly on this internal struct layout.

Thanks,

Bhavesh Maheshwari
Engineer
+91 8827543501
[email protected]<mailto:[email protected]>
[cid:a6d6c0b2-4532-484b-9ec6-adca64de6f13]<https://www.einfochips.com/>
________________________________
From: [email protected] 
<[email protected]> on behalf of Yoann Congal via 
lists.openembedded.org <[email protected]>
Sent: 27 September 2026 02:07
To: Bhavesh Rajesh Maheshwari <[email protected]>; 
[email protected] 
<[email protected]>
Subject: [External] Re: [wrynose][oe-core][PATCH 5/5] ffmpeg: Fix for 
CVE-2026-66041


CAUTION: This email originated from outside of the organization. This message 
might not be safe, use caution in opening it. If in doubt, do not open the 
attachment nor links in the message.


On Tue Sep 22, 2026 at 9:01 AM CEST, Bhavesh R Maheshwari via 
lists.openembedded.org wrote:
> From: Bhavesh R Maheshwari <[email protected]>
>
> Pick the patch from [1], also referenced in the NVD report [2].
>
> [1] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2F4da9812e25894fb51d62a8875cfa8eb39b5e20f5&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7fe67053ed514d0a521d08df1c0df794%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260518444725508%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yXRkqouFPx5rn7HcXqCIyLYvG6DGjw%2F5lRPYq544zPg%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5>
> [2] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2Fcve-2026-66041&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7fe67053ed514d0a521d08df1c0df794%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260518444753817%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=UvlOY1pB7KYXkF5k%2Bgyx5DEihvVKJ3yojDR%2F7QLFNpg%3D&reserved=0<https://nvd.nist.gov/vuln/detail/cve-2026-66041>
>
> Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> ---
>  .../ffmpeg/ffmpeg/CVE-2026-66041.patch        | 60 +++++++++++++++++++
>  .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
>  2 files changed, 61 insertions(+)
>  create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
>
> diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch 
> b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
> new file mode 100644
> index 0000000000..7a8c4e0c8b
> --- /dev/null
> +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
> @@ -0,0 +1,60 @@
> +From 9db6b5816516b85e981e177863b2eb361dbec3c8 Mon Sep 17 00:00:00 2001
> +From: Michael Niedermayer <[email protected]>
> +Date: Sun, 28 Jun 2026 15:33:38 +0200
> +Subject: [PATCH] avfilter/vf_quirc: resize the quirc buffers when the input
> + size changes
> +
> +Fixes: out of array access
> +Fixes: JbvzNObhorBp
> +Fixes: 030e140145 (lavfi: add quirc filter)
> +Found-by: Adrian Junge (vurlo)
> +Signed-off-by: Michael Niedermayer <[email protected]>
> +
> +CVE: CVE-2026-66041
> +Upstream-Status: Backport 
> [https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2F4da9812e25894fb51d62a8875cfa8eb39b5e20f5&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7fe67053ed514d0a521d08df1c0df794%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260518444773405%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=fL9bPK6QDy%2FfoOT4NV2UwWLNCNW3NU12RP0eKmsBr7Q%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5>]
> +
> +Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> +---
> + libavfilter/vf_quirc.c | 12 ++++++++++++
> + 1 file changed, 12 insertions(+)
> +
> +diff --git a/libavfilter/vf_quirc.c b/libavfilter/vf_quirc.c
> +index 59dc84caa8..d2ba48e7bc 100644
> +--- a/libavfilter/vf_quirc.c
> ++++ b/libavfilter/vf_quirc.c
> +@@ -36,6 +36,7 @@ typedef struct QuircContext {
> +     const AVClass *class;
> +
> +     struct quirc *quirc;
> ++    int width, height;
> + } QuircContext;

Same question as 1/5: 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ffmpeg.org%2Fdoxygen%2F8.0%2FstructQuircContext.html&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7fe67053ed514d0a521d08df1c0df794%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260518444792117%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=xB5mU5FhBShAJ7zomz7F7lBWu2BBpYTDKNAdGXAR0QM%3D&reserved=0<https://www.ffmpeg.org/doxygen/8.0/structQuircContext.html>
Are you sure this does not break existing code?

FYI, for the series as a whole: Since 2-4/5 are indenpendant of 1,5/5,
I'll keep 2-4/5 in my branch for tests/reviews but hold 1,5/5 while we
clarify the API change.

Thanks!
--
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#247238): 
https://lists.openembedded.org/g/openembedded-core/message/247238
Mute This Topic: https://lists.openembedded.org/mt/121370959/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to