Commit 3d1023f1bd for ffmpeg

commit 3d1023f1bde5aed2430f89b67fa65ca10730b442
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Wed Oct 7 02:50:32 2026 +0200

    avformat/rtpenc_vc2hq: Reject transform parameters longer than 65535 bytes

    Not a security issue.

    Fixes: GOnB0bwaMBbJ
    Truncated transform parameters Replicated through UnModified FFmpeg
    Found during triage of the security report nd3rLqSpKgo5

diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index f7689f7d8f..7a422910bb 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -58,7 +58,7 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
     GetBitContext gc;
     int lvl, second_field;
     uint32_t pic_nr, wavelet_depth, prefix_bytes, size_scaler;
-    uint16_t frag_len;
+    int frag_len;
     char *info_hdr = &rtp_ctx->buf[4];

     if (size < DIRAC_PIC_NR_SIZE)
@@ -88,7 +88,7 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
     }

     frag_len = (get_bits_count(&gc) + 7) / 8; /* length of transform parameters */
-    if (get_bits_left(&gc) < 0)
+    if (get_bits_left(&gc) < 0 || frag_len > UINT16_MAX)
         return AVERROR_INVALIDDATA;

     AV_WB32(&info_hdr[ 0], pic_nr);