Commit 3d1023f1bd for ffmpeg
commit 3d1023f1bde5aed2430f89b67fa65ca10730b442
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Wed Oct 7 02:50:32 2026 +0200
avformat/rtpenc_vc2hq: Reject transform parameters longer than 65535 bytes
Not a security issue.
Fixes: GOnB0bwaMBbJ
Truncated transform parameters Replicated through UnModified FFmpeg
Found during triage of the security report nd3rLqSpKgo5
diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index f7689f7d8f..7a422910bb 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -58,7 +58,7 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
GetBitContext gc;
int lvl, second_field;
uint32_t pic_nr, wavelet_depth, prefix_bytes, size_scaler;
- uint16_t frag_len;
+ int frag_len;
char *info_hdr = &rtp_ctx->buf[4];
if (size < DIRAC_PIC_NR_SIZE)
@@ -88,7 +88,7 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
}
frag_len = (get_bits_count(&gc) + 7) / 8; /* length of transform parameters */
- if (get_bits_left(&gc) < 0)
+ if (get_bits_left(&gc) < 0 || frag_len > UINT16_MAX)
return AVERROR_INVALIDDATA;
AV_WB32(&info_hdr[ 0], pic_nr);