Commit 301a611370 for ffmpeg

commit 301a611370a0ba81f4a71d3b7ccd064623606c1b
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Tue Oct 6 07:10:44 2026 +0200

    avformat/imf_cpl: Do not free the marker label on scope allocation failure

    Fixes: double free
    Fixes: JLKmGHU1qVX5
    Fixes: AISLE-2026-0111-00365
    Double free Replicated through API with ASAN and an injected libxml2 allocation failure
    Found-by: Joshua Rogers <joshua.rogers@aisle.com>

diff --git a/libavformat/imf_cpl.c b/libavformat/imf_cpl.c
index 8c3530f412..dba502007c 100644
--- a/libavformat/imf_cpl.c
+++ b/libavformat/imf_cpl.c
@@ -311,10 +311,8 @@ static int fill_marker(xmlNodePtr marker_elem, FFIMFMarker *marker)
     if (!(marker->scope_utf8 = xmlGetNoNsProp(element, "scope"))) {
         marker->scope_utf8
             = xmlCharStrdup("http://www.smpte-ra.org/schemas/2067-3/2013#standard-markers");
-        if (!marker->scope_utf8) {
-            xmlFree(marker->label_utf8);
+        if (!marker->scope_utf8)
             return AVERROR(ENOMEM);
-        }
     }

     return ret;