On Tue Sep 22, 2026 at 9:01 AM CEST, Bhavesh R Maheshwari via 
lists.openembedded.org wrote:
> From: Bhavesh R Maheshwari <[email protected]>
>
> Pick the patch from [1], also referenced in the NVD report [2].
>
> [1] 
> https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5
> [2] https://nvd.nist.gov/vuln/detail/cve-2026-66041
>
> Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> ---
>  .../ffmpeg/ffmpeg/CVE-2026-66041.patch        | 60 +++++++++++++++++++
>  .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
>  2 files changed, 61 insertions(+)
>  create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
>
> diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch 
> b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
> new file mode 100644
> index 0000000000..7a8c4e0c8b
> --- /dev/null
> +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66041.patch
> @@ -0,0 +1,60 @@
> +From 9db6b5816516b85e981e177863b2eb361dbec3c8 Mon Sep 17 00:00:00 2001
> +From: Michael Niedermayer <[email protected]>
> +Date: Sun, 28 Jun 2026 15:33:38 +0200
> +Subject: [PATCH] avfilter/vf_quirc: resize the quirc buffers when the input
> + size changes
> +
> +Fixes: out of array access
> +Fixes: JbvzNObhorBp
> +Fixes: 030e140145 (lavfi: add quirc filter)
> +Found-by: Adrian Junge (vurlo)
> +Signed-off-by: Michael Niedermayer <[email protected]>
> +
> +CVE: CVE-2026-66041
> +Upstream-Status: Backport 
> [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5]
> +
> +Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> +---
> + libavfilter/vf_quirc.c | 12 ++++++++++++
> + 1 file changed, 12 insertions(+)
> +
> +diff --git a/libavfilter/vf_quirc.c b/libavfilter/vf_quirc.c
> +index 59dc84caa8..d2ba48e7bc 100644
> +--- a/libavfilter/vf_quirc.c
> ++++ b/libavfilter/vf_quirc.c
> +@@ -36,6 +36,7 @@ typedef struct QuircContext {
> +     const AVClass *class;
> + 
> +     struct quirc *quirc;
> ++    int width, height;
> + } QuircContext;

Same question as 1/5: https://www.ffmpeg.org/doxygen/8.0/structQuircContext.html
Are you sure this does not break existing code?

FYI, for the series as a whole: Since 2-4/5 are indenpendant of 1,5/5,
I'll keep 2-4/5 in my branch for tests/reviews but hold 1,5/5 while we
clarify the API change.

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246643): 
https://lists.openembedded.org/g/openembedded-core/message/246643
Mute This Topic: https://lists.openembedded.org/mt/121370959/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to