Commit 404c2e47cf for ffmpeg
commit 404c2e47cf9af8ed7c607042c6d4a5bfcd3c593f
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Sep 29 01:57:32 2026 +0200
avcodec/options_table: make rc_override_count read-only
The (to me) known exploit path requires writing the usere preset files
(which is unpractical)
Fixes: heap out of array read in get_qscale()
Fixes: TFN283cBZrlk
Found-by: Hongduo Zhao
Replicated through UnModified FFmpeg
diff --git a/libavcodec/options_table.h b/libavcodec/options_table.h
index 100095b24c..a329a84db1 100644
--- a/libavcodec/options_table.h
+++ b/libavcodec/options_table.h
@@ -144,7 +144,7 @@ static const AVOption avcodec_options[] = {
{"aggressive", "consider things that a sane encoder should not do as an error", 0, AV_OPT_TYPE_CONST, {.i64 = AV_EF_AGGRESSIVE | AV_EF_COMPLIANT | AV_EF_CAREFUL}, INT_MIN, INT_MAX, A|V|S|D|E, .unit = "err_detect"},
{"has_b_frames", NULL, OFFSET(has_b_frames), AV_OPT_TYPE_INT, {.i64 = DEFAULT }, 0, INT_MAX},
{"block_align", NULL, OFFSET(block_align), AV_OPT_TYPE_INT, {.i64 = DEFAULT }, 0, INT_MAX},
-{"rc_override_count", NULL, OFFSET(rc_override_count), AV_OPT_TYPE_INT, {.i64 = DEFAULT }, INT_MIN, INT_MAX},
+{"rc_override_count", NULL, OFFSET(rc_override_count), AV_OPT_TYPE_INT, {.i64 = DEFAULT }, INT_MIN, INT_MAX, AV_OPT_FLAG_READONLY},
{"maxrate", "maximum bitrate (in bits/s). Used for VBV together with bufsize.", OFFSET(rc_max_rate), AV_OPT_TYPE_INT64, {.i64 = DEFAULT }, 0, INT_MAX, V|A|E},
{"minrate", "minimum bitrate (in bits/s). Most useful in setting up a CBR encode. It is of little use otherwise.",
OFFSET(rc_min_rate), AV_OPT_TYPE_INT64, {.i64 = DEFAULT }, INT_MIN, INT_MAX, V|A|E},