Hi Yoann, Thanks for raising this. I checked the QuircContext definition and verified the build with the patch applied. QuircContext is defined in libavfilter/vf_quirc.c and used only as the quirc filter’s private context. The new width and height fields enlarge that private context; they do not change a public FFmpeg API or a caller-visible structure. The Doxygen page lists the struct because it is present in the source, but it is not evidence that the struct is part of the public API. The patch records the configured dimensions and resizes the quirc buffer if a later frame has different dimensions. I don’t see a compatibility issue for existing supported code.
Thanks Bhavesh Maheshwari Engineer +91 8827543501 [email protected]<mailto:[email protected]> [cid:b7627589-92e3-4ba8-b5bd-95367dfda157]<https://www.einfochips.com/> ________________________________ From: Yoann Congal <[email protected]> Sent: 27 September 2026 01:28 To: Bhavesh Rajesh Maheshwari <[email protected]>; [email protected] <[email protected]> Subject: [External] Re: [wrynose][oe-core][PATCH 1/5] ffmpeg: Fix for CVE-2026-66036 CAUTION: This email originated from outside of the organization. This message might not be safe, use caution in opening it. If in doubt, do not open the attachment nor links in the message. On Tue Sep 22, 2026 at 9:01 AM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote: > From: Bhavesh R Maheshwari <[email protected]> > > Pick the patch from [1] and [2], mentioned in PR#23783 [3] which is > referenced in the NVD report [4] > > [1] > https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2Ff0f634b6585fdc7bbb43ab3ae461499bfca9ad2e&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345529147%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=zvgjZiEO2XkQjfn7J5KJCJN8wQEAxqgM9fKJ103HPVQ%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e> > [2] > https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2F5d7112c60e6f0f0742ce47d448e6da0718a70f4c&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345585689%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rDzwxbj4D6E%2BKtO69vqAdljWFAWdiuhPay8mzI2nkDM%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c> > [3] > https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23783&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345626523%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=ligCIg0tGRHfsFtp3l3p7ieKfT%2FaOjCwoc80XwdbnK4%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783> > [4] > https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2Fcve-2026-66036&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345659261%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=38KssgC9DDjSA7qbSyEmWzXix%2FkX1UekEjx015o3DYU%3D&reserved=0<https://nvd.nist.gov/vuln/detail/cve-2026-66036> > > Signed-off-by: Bhavesh R Maheshwari <[email protected]> > --- > .../ffmpeg/ffmpeg/CVE-2026-66036_p1.patch | 120 ++++++++++++++++++ > .../ffmpeg/ffmpeg/CVE-2026-66036_p2.patch | 71 +++++++++++ > .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 2 + > 3 files changed, 193 insertions(+) > create mode 100644 > meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch > create mode 100644 > meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch > > diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch > b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch > new file mode 100644 > index 0000000000..bce0265114 > --- /dev/null > +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch > @@ -0,0 +1,120 @@ > +From 7ac88955c4678fc10cc44a786ff9bf724bb12deb Mon Sep 17 00:00:00 2001 > +From: Michael Niedermayer <[email protected]> > +Date: Sun, 12 Jul 2026 13:05:07 +0200 > +Subject: [PATCH 1/2] avfilter/vf_hqdn3d: reject unsupported frame parameter > + changes > + > +Fixes: out of array access > +Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py > +Fixes: wWDsy2oDvMuR > +Found-by: Adrian Junge (vurlo) <[email protected]> > + > +CVE: CVE-2026-66036 > +Upstream-Status: Backport > [https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2Ff0f634b6585fdc7bbb43ab3ae461499bfca9ad2e&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345690477%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=KleDBcKlFXLeKVD1vYsjjgUuhemdi%2FJNocGwhbit2l8%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e>] > + > +Signed-off-by: Bhavesh R Maheshwari <[email protected]> > +--- > + libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++--------- > + libavfilter/vf_hqdn3d.h | 2 ++ > + 2 files changed, 27 insertions(+), 9 deletions(-) > + > +diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h > +index 3279bbcc77..3467f27145 100644 > +--- a/libavfilter/vf_hqdn3d.h > ++++ b/libavfilter/vf_hqdn3d.h > +@@ -36,6 +36,8 @@ typedef struct HQDN3DContext { > + double strength[4]; > + int hsub, vsub; > + int depth; > ++ int width, height; > ++ enum AVPixelFormat format; > + void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, > uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal); > + } HQDN3DContext; Hello, This change touches exposed/documented API: https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ffmpeg.org%2Fdoxygen%2F8.0%2FstructHQDN3DContext.html&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345715588%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rJt9AoaQCIyipSiOxP1rMdq2sR6ez9%2Fvh6lZxpc0Mgo%3D&reserved=0<https://www.ffmpeg.org/doxygen/8.0/structHQDN3DContext.html> Are you sure this does not break existing code? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246745): https://lists.openembedded.org/g/openembedded-core/message/246745 Mute This Topic: https://lists.openembedded.org/mt/121370954/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
