On Tue Sep 22, 2026 at 9:01 AM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote: > From: Bhavesh R Maheshwari <[email protected]> > > Pick the patch from [1], also referenced in the NVD report [2]. > > [1] > https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5 > [2] https://nvd.nist.gov/vuln/detail/cve-2026-66041 > > Signed-off-by: Bhavesh R Maheshwari <[email protected]> > --- > .../ffmpeg/ffmpeg/CVE-2026-66041.patch | 60 +++++++++++++++++++ > .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + > 2 files changed, 61 insertions(+) > create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch > > diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch > b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch > new file mode 100644 > index 0000000000..7a8c4e0c8b > --- /dev/null > +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch > @@ -0,0 +1,60 @@ > +From 9db6b5816516b85e981e177863b2eb361dbec3c8 Mon Sep 17 00:00:00 2001 > +From: Michael Niedermayer <[email protected]> > +Date: Sun, 28 Jun 2026 15:33:38 +0200 > +Subject: [PATCH] avfilter/vf_quirc: resize the quirc buffers when the input > + size changes > + > +Fixes: out of array access > +Fixes: JbvzNObhorBp > +Fixes: 030e140145 (lavfi: add quirc filter) > +Found-by: Adrian Junge (vurlo) > +Signed-off-by: Michael Niedermayer <[email protected]> > + > +CVE: CVE-2026-66041 > +Upstream-Status: Backport > [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5] > + > +Signed-off-by: Bhavesh R Maheshwari <[email protected]> > +--- > + libavfilter/vf_quirc.c | 12 ++++++++++++ > + 1 file changed, 12 insertions(+) > + > +diff --git a/libavfilter/vf_quirc.c b/libavfilter/vf_quirc.c > +index 59dc84caa8..d2ba48e7bc 100644 > +--- a/libavfilter/vf_quirc.c > ++++ b/libavfilter/vf_quirc.c > +@@ -36,6 +36,7 @@ typedef struct QuircContext { > + const AVClass *class; > + > + struct quirc *quirc; > ++ int width, height; > + } QuircContext;
Same question as 1/5: https://www.ffmpeg.org/doxygen/8.0/structQuircContext.html Are you sure this does not break existing code? FYI, for the series as a whole: Since 2-4/5 are indenpendant of 1,5/5, I'll keep 2-4/5 in my branch for tests/reviews but hold 1,5/5 while we clarify the API change. Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246643): https://lists.openembedded.org/g/openembedded-core/message/246643 Mute This Topic: https://lists.openembedded.org/mt/121370959/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
