From: Bhavesh R Maheshwari <[email protected]> Pick the patch from [1] and [2], mentioned in PR#23780 [3] which is referenced in the NVD report [4]
[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79 [2] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c [3] https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780 [4] https://nvd.nist.gov/vuln/detail/cve-2026-65705 Signed-off-by: Bhavesh R Maheshwari <[email protected]> --- changes in v2: - rebased on new CVE fix --- .../ffmpeg/ffmpeg/CVE-2026-65705_p1.patch | 68 +++++++++++ .../ffmpeg/ffmpeg/CVE-2026-65705_p2.patch | 115 ++++++++++++++++++ .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 2 + 3 files changed, 185 insertions(+) create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch new file mode 100644 index 0000000000..e331cb9646 --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch @@ -0,0 +1,68 @@ +From f73f6cd9a5f230ce02afbc6a74172400b92b1127 Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer <[email protected]> +Date: Sat, 11 Jul 2026 16:47:28 +0200 +Subject: [PATCH 7/9] avfilter/vf_floodfill: size the point stack for the + current frame + +Fixes: out of array access +Fixes: 8aj_floodfill_dynamic_size.pgm / 8aj_generate_floodfill_dynamic_size_pgm.py +Fixes: 3MleMXjGZvu3 +Found-by: Adrian Junge (vurlo) <[email protected]> + +CVE: CVE-2026-65705 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79] + +Signed-off-by: Bhavesh R Maheshwari <[email protected]> +--- + libavfilter/vf_floodfill.c | 19 ++++++++++++++++--- + 1 file changed, 16 insertions(+), 3 deletions(-) + +diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c +index 6d89963..e569d5f 100644 +--- a/libavfilter/vf_floodfill.c ++++ b/libavfilter/vf_floodfill.c +@@ -41,6 +41,7 @@ typedef struct FloodfillContext { + int nb_planes; + int back, front; + Points *points; ++ unsigned int points_size; + + int (*is_same)(const AVFrame *frame, int x, int y, + unsigned s0, unsigned s1, unsigned s2, unsigned s3); +@@ -271,9 +272,6 @@ static int config_input(AVFilterLink *inlink) + } + + s->front = s->back = 0; +- s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points)); +- if (!s->points) +- return AVERROR(ENOMEM); + + return 0; + } +@@ -292,8 +290,23 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + int s3 = s->s[3]; + const int w = frame->width; + const int h = frame->height; ++ size_t nb_points, points_size; + int i, ret; + ++ if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 || ++ av_size_mult(w, h, &nb_points) < 0 || ++ av_size_mult(nb_points, 4 * sizeof(*s->points), &points_size) < 0) { ++ av_frame_free(&frame); ++ return AVERROR(EINVAL); ++ } ++ ++ av_fast_malloc(&s->points, &s->points_size, points_size); ++ if (!s->points) { ++ av_frame_free(&frame); ++ return AVERROR(ENOMEM); ++ } ++ s->front = s->back = 0; ++ + if (is_inside(s->x, s->y, w, h)) { + s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); + +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch new file mode 100644 index 0000000000..91a304015f --- /dev/null +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch @@ -0,0 +1,115 @@ +From 7f99588c7fc27526a2d73dddc91e4cd57a3b401c Mon Sep 17 00:00:00 2001 +From: Michael Niedermayer <[email protected]> +Date: Sun, 12 Jul 2026 03:27:47 +0200 +Subject: [PATCH 8/9] avfilter/vf_floodfill: remove unneeded variables + +Signed-off-by: Michael Niedermayer <[email protected]> + +CVE: CVE-2026-65705 +Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c] + +Signed-off-by: Bhavesh R Maheshwari <[email protected]> +--- + libavfilter/vf_floodfill.c | 35 ++++++++++++++++------------------- + 1 file changed, 16 insertions(+), 19 deletions(-) + +diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c +index e569d5f..9bc72e2 100644 +--- a/libavfilter/vf_floodfill.c ++++ b/libavfilter/vf_floodfill.c +@@ -39,7 +39,6 @@ typedef struct FloodfillContext { + int d[4]; + + int nb_planes; +- int back, front; + Points *points; + unsigned int points_size; + +@@ -271,8 +270,6 @@ static int config_input(AVFilterLink *inlink) + } + } + +- s->front = s->back = 0; +- + return 0; + } + +@@ -292,6 +289,7 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + const int h = frame->height; + size_t nb_points, points_size; + int i, ret; ++ int front = 0; + + if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 || + av_size_mult(w, h, &nb_points) < 0 || +@@ -305,7 +303,6 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + av_frame_free(&frame); + return AVERROR(ENOMEM); + } +- s->front = s->back = 0; + + if (is_inside(s->x, s->y, w, h)) { + s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); +@@ -323,9 +320,9 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + goto end; + + if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) { +- s->points[s->front].x = s->x; +- s->points[s->front].y = s->y; +- s->front++; ++ s->points[front].x = s->x; ++ s->points[front].y = s->y; ++ front++; + } + + if (ret = ff_inlink_make_frame_writable(link, &frame)) { +@@ -333,34 +330,34 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame) + return ret; + } + +- while (s->front > s->back) { ++ while (front > 0) { + int x, y; + +- s->front--; +- x = s->points[s->front].x; +- y = s->points[s->front].y; ++ front--; ++ x = s->points[front].x; ++ y = s->points[front].y; + + if (s->is_same(frame, x, y, s0, s1, s2, s3)) { + s->set_pixel(frame, x, y, d0, d1, d2, d3); + + if (is_inside(x + 1, y, w, h)) { +- s->points[s->front] .x = x + 1; +- s->points[s->front++].y = y; ++ s->points[front] .x = x + 1; ++ s->points[front++].y = y; + } + + if (is_inside(x - 1, y, w, h)) { +- s->points[s->front] .x = x - 1; +- s->points[s->front++].y = y; ++ s->points[front] .x = x - 1; ++ s->points[front++].y = y; + } + + if (is_inside(x, y + 1, w, h)) { +- s->points[s->front] .x = x; +- s->points[s->front++].y = y + 1; ++ s->points[front] .x = x; ++ s->points[front++].y = y + 1; + } + + if (is_inside(x, y - 1, w, h)) { +- s->points[s->front] .x = x; +- s->points[s->front++].y = y - 1; ++ s->points[front] .x = x; ++ s->points[front++].y = y - 1; + } + } + } +-- +2.43.0 + diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb index 82f4b221b7..e39961c649 100644 --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb @@ -34,6 +34,8 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \ file://CVE-2026-64835.patch \ file://CVE-2026-65703.patch \ file://CVE-2026-65704.patch \ + file://CVE-2026-65705_p1.patch \ + file://CVE-2026-65705_p2.patch \ " SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818" -- 2.43.0
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245963): https://lists.openembedded.org/g/openembedded-core/message/245963 Mute This Topic: https://lists.openembedded.org/mt/121277109/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
