From: Bhavesh R Maheshwari <[email protected]> Pick the patch from [1], also referenced in the NVD report [2].
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-65706 Signed-off-by: Bhavesh R Maheshwari <[email protected]> --- changes in v2: - rebased on new CVE fix --- .../ffmpeg/ffmpeg/CVE-2026-65706.patch | 52 +++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + 2 files changed, 53 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch new file mode 100644 index 0000000000..7311ed71c0 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch @@ -0,0 +1,52 @@ +From 825f9e837f88c0c6983b5ccb70f91a32e9168f3c Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer <[email protected]> +Date: Sat, 11 Jul 2026 16:46:39 +0200 +Subject: [PATCH 9/9] avfilter/vf_swaprect: size the temp row buffer for the + widest plane + +Fixes: out of array access +Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py +Fixes: VRAXYvKtmKa8 +Found-by: Adrian Junge (vurlo) <[email protected]> + +CVE: CVE-2026-65706 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527] + +Signed-off-by: Bhavesh R Maheshwari <[email protected]> +--- + libavfilter/vf_swaprect.c | 12 +++++++++++- + 1 file changed, 11 insertions(+), 1 deletion(-) + +diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c +index 5d93f51..fe007ee 100644 +--- a/libavfilter/vf_swaprect.c ++++ b/libavfilter/vf_swaprect.c +@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink) + { + AVFilterContext *ctx = inlink->dst; + SwapRectContext *s = ctx->priv; ++ int size = 0; + + if (!s->w || !s->h || + !s->x1 || !s->y1 || +@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink) + av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc); + s->nb_planes = av_pix_fmt_count_planes(inlink->format); + +- s->temp = av_malloc_array(inlink->w, s->pixsteps[0]); ++ for (int p = 0; p < s->nb_planes; p++) { ++ int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0; ++ int width = AV_CEIL_RSHIFT(inlink->w, shift); ++ ++ if (width > INT_MAX / s->pixsteps[p]) ++ return AVERROR(EINVAL); ++ size = FFMAX(size, width * s->pixsteps[p]); ++ } ++ ++ s->temp = av_malloc(size); + if (!s->temp) + return AVERROR(ENOMEM); + +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index e39961c649..48ece24760 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -36,6 +36,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-65704.patch \ file://CVE-2026-65705_p1.patch \ file://CVE-2026-65705_p2.patch \ + file://CVE-2026-65706.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" -- 2.43.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245964): https://lists.openembedded.org/g/openembedded-core/message/245964 Mute This Topic: https://lists.openembedded.org/mt/121277111/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
