Hi Yoann,
Thanks for raising this. I checked the QuircContext definition and verified the 
build with the patch applied.
QuircContext is defined in libavfilter/vf_quirc.c and used only as the quirc 
filter’s private context. The new width and height fields enlarge that private 
context; they do not change a public FFmpeg API or a caller-visible structure. 
The Doxygen page lists the struct because it is present in the source, but it 
is not evidence that the struct is part of the public API.
The patch records the configured dimensions and resizes the quirc buffer if a 
later frame has different dimensions. I don’t see a compatibility issue for 
existing supported code.


Thanks

Bhavesh Maheshwari
Engineer
+91 8827543501
[email protected]<mailto:[email protected]>
[cid:b7627589-92e3-4ba8-b5bd-95367dfda157]<https://www.einfochips.com/>
________________________________
From: Yoann Congal <[email protected]>
Sent: 27 September 2026 01:28
To: Bhavesh Rajesh Maheshwari <[email protected]>; 
[email protected] 
<[email protected]>
Subject: [External] Re: [wrynose][oe-core][PATCH 1/5] ffmpeg: Fix for 
CVE-2026-66036


CAUTION: This email originated from outside of the organization. This message 
might not be safe, use caution in opening it. If in doubt, do not open the 
attachment nor links in the message.


On Tue Sep 22, 2026 at 9:01 AM CEST, Bhavesh R Maheshwari via 
lists.openembedded.org wrote:
> From: Bhavesh R Maheshwari <[email protected]>
>
> Pick the patch from [1] and [2], mentioned in PR#23783 [3] which is
> referenced in the NVD report [4]
>
> [1] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2Ff0f634b6585fdc7bbb43ab3ae461499bfca9ad2e&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345529147%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=zvgjZiEO2XkQjfn7J5KJCJN8wQEAxqgM9fKJ103HPVQ%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e>
> [2] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2F5d7112c60e6f0f0742ce47d448e6da0718a70f4c&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345585689%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rDzwxbj4D6E%2BKtO69vqAdljWFAWdiuhPay8mzI2nkDM%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c>
> [3] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23783&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345626523%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=ligCIg0tGRHfsFtp3l3p7ieKfT%2FaOjCwoc80XwdbnK4%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783>
> [4] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2Fcve-2026-66036&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345659261%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=38KssgC9DDjSA7qbSyEmWzXix%2FkX1UekEjx015o3DYU%3D&reserved=0<https://nvd.nist.gov/vuln/detail/cve-2026-66036>
>
> Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> ---
>  .../ffmpeg/ffmpeg/CVE-2026-66036_p1.patch     | 120 ++++++++++++++++++
>  .../ffmpeg/ffmpeg/CVE-2026-66036_p2.patch     |  71 +++++++++++
>  .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |   2 +
>  3 files changed, 193 insertions(+)
>  create mode 100644 
> meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch
>  create mode 100644 
> meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p2.patch
>
> diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch 
> b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch
> new file mode 100644
> index 0000000000..bce0265114
> --- /dev/null
> +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-66036_p1.patch
> @@ -0,0 +1,120 @@
> +From 7ac88955c4678fc10cc44a786ff9bf724bb12deb Mon Sep 17 00:00:00 2001
> +From: Michael Niedermayer <[email protected]>
> +Date: Sun, 12 Jul 2026 13:05:07 +0200
> +Subject: [PATCH 1/2] avfilter/vf_hqdn3d: reject unsupported frame parameter
> + changes
> +
> +Fixes: out of array access
> +Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py
> +Fixes: wWDsy2oDvMuR
> +Found-by: Adrian Junge (vurlo) <[email protected]>
> +
> +CVE: CVE-2026-66036
> +Upstream-Status: Backport 
> [https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fcommit%2Ff0f634b6585fdc7bbb43ab3ae461499bfca9ad2e&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345690477%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=KleDBcKlFXLeKVD1vYsjjgUuhemdi%2FJNocGwhbit2l8%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e>]
> +
> +Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> +---
> + libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++---------
> + libavfilter/vf_hqdn3d.h |  2 ++
> + 2 files changed, 27 insertions(+), 9 deletions(-)
> +
> +diff --git a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h
> +index 3279bbcc77..3467f27145 100644
> +--- a/libavfilter/vf_hqdn3d.h
> ++++ b/libavfilter/vf_hqdn3d.h
> +@@ -36,6 +36,8 @@ typedef struct HQDN3DContext {
> +     double strength[4];
> +     int hsub, vsub;
> +     int depth;
> ++    int width, height;
> ++    enum AVPixelFormat format;
> +     void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, 
> uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal);
> + } HQDN3DContext;

Hello,

This change touches exposed/documented API: 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ffmpeg.org%2Fdoxygen%2F8.0%2FstructHQDN3DContext.html&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7Cc5cd2b5126294b9c4d9108df1c0894f4%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639260495345715588%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rJt9AoaQCIyipSiOxP1rMdq2sR6ez9%2Fvh6lZxpc0Mgo%3D&reserved=0<https://www.ffmpeg.org/doxygen/8.0/structHQDN3DContext.html>
Are you sure this does not break existing code?

Thanks!
--
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246745): 
https://lists.openembedded.org/g/openembedded-core/message/246745
Mute This Topic: https://lists.openembedded.org/mt/121370954/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to