From: Bhavesh R Maheshwari <[email protected]>

Pick the patch from [1], also referenced in the NVD report [2].

[1] 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65706

Signed-off-by: Bhavesh R Maheshwari <[email protected]>
---
changes in v2:
- rebased on new CVE fix
---
 .../ffmpeg/ffmpeg/CVE-2026-65706.patch        | 52 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 53 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch

diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch 
b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
new file mode 100644
index 0000000000..7311ed71c0
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
@@ -0,0 +1,52 @@
+From 825f9e837f88c0c6983b5ccb70f91a32e9168f3c Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <[email protected]>
+Date: Sat, 11 Jul 2026 16:46:39 +0200
+Subject: [PATCH 9/9] avfilter/vf_swaprect: size the temp row buffer for the
+ widest plane
+
+Fixes: out of array access
+Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
+Fixes: VRAXYvKtmKa8
+Found-by: Adrian Junge (vurlo) <[email protected]>
+
+CVE: CVE-2026-65706
+Upstream-Status: Backport 
[https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527]
+
+Signed-off-by: Bhavesh R Maheshwari <[email protected]>
+---
+ libavfilter/vf_swaprect.c | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c
+index 5d93f51..fe007ee 100644
+--- a/libavfilter/vf_swaprect.c
++++ b/libavfilter/vf_swaprect.c
+@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink)
+ {
+     AVFilterContext *ctx = inlink->dst;
+     SwapRectContext *s = ctx->priv;
++    int size = 0;
+ 
+     if (!s->w  || !s->h  ||
+         !s->x1 || !s->y1 ||
+@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink)
+     av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc);
+     s->nb_planes = av_pix_fmt_count_planes(inlink->format);
+ 
+-    s->temp = av_malloc_array(inlink->w, s->pixsteps[0]);
++    for (int p = 0; p < s->nb_planes; p++) {
++        int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0;
++        int width = AV_CEIL_RSHIFT(inlink->w, shift);
++
++        if (width > INT_MAX / s->pixsteps[p])
++            return AVERROR(EINVAL);
++        size = FFMAX(size, width * s->pixsteps[p]);
++    }
++
++    s->temp = av_malloc(size);
+     if (!s->temp)
+         return AVERROR(ENOMEM);
+ 
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb 
b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index e39961c649..48ece24760 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -36,6 +36,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://CVE-2026-65704.patch \
            file://CVE-2026-65705_p1.patch \
            file://CVE-2026-65705_p2.patch \
+           file://CVE-2026-65706.patch \
            "
 
 SRC_URI[sha256sum] = 
"6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245964): 
https://lists.openembedded.org/g/openembedded-core/message/245964
Mute This Topic: https://lists.openembedded.org/mt/121277111/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to