Commit 3322ac1646 for ffmpeg
commit 3322ac16469fc82695bbc2e3e286f01acf8addbc
Author: Niklas Haas <git@haasn.dev>
Date: Sat Sep 5 13:51:57 2026 +0200
avformat/libcurl: guard against overflow from undelimited responses
verify_content_range() already clamps down on the valid byte range for
206 replies (or 200 replies with a Content-Length), but an undelimited
response represents an escape path that can still trigger overflow here.
Signed-off-by: Niklas Haas <git@haasn.dev>
diff --git a/libavformat/libcurl.c b/libavformat/libcurl.c
index d8dc44d652..57e413df05 100644
--- a/libavformat/libcurl.c
+++ b/libavformat/libcurl.c
@@ -240,6 +240,19 @@ static size_t write_callback(char *ptr, size_t size, size_t nmemb, void *userdat
return bytes; /* discard */
}
+ /* Prevent overflow / non-addressable byte ranges */
+ if (bytes > INT64_MAX - c->request_start - c->request_received) {
+ av_log(c->h, AV_LOG_ERROR, "Server sent back more data than addressable "
+ "at offset %"PRId64"\n", c->request_start);
+ c->loop->num_errors++;
+ c->stream_ok = 0;
+ if (!c->status)
+ c->status = AVERROR(ERANGE);
+ pthread_cond_broadcast(&c->cond);
+ pthread_mutex_unlock(&c->mutex);
+ return CURL_WRITEFUNC_ERROR;
+ }
+
space = av_fifo_can_write(c->fifo);
if (space < bytes) {
/* pause the transfer and wait for the consumer to drain. */