Commit 5c25cb3453 for ffmpeg
commit 5c25cb34530c11e4da2cc6fdccfacba1f261f74e
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Wed Oct 7 03:39:30 2026 +0200
avformat/rtpenc_vc2hq: Write the extended sequence number
RFC 8450 requires the high order 16 bits of the 32 bit packet sequence
number in the payload header, 0 was always written. Count the wraps of
the RTP sequence number in the RTP muxer.
Not a security issue.
Found during triage of the security report HRhmcrDPRPyf
diff --git a/libavformat/rtpenc.c b/libavformat/rtpenc.c
index dd08a9bbcb..7f09329b10 100644
--- a/libavformat/rtpenc.c
+++ b/libavformat/rtpenc.c
@@ -384,6 +384,8 @@ void ff_rtp_send_data(AVFormatContext *s1, const uint8_t *buf1, int len, int m)
avio_flush(s1->pb);
s->seq = (s->seq + 1) & 0xffff;
+ if (!s->seq)
+ s->seq_high++;
s->octet_count += len;
s->packet_count++;
}
diff --git a/libavformat/rtpenc.h b/libavformat/rtpenc.h
index ba88bfefc0..3ef02ac10d 100644
--- a/libavformat/rtpenc.h
+++ b/libavformat/rtpenc.h
@@ -32,6 +32,7 @@ struct RTPMuxContext {
uint32_t ssrc;
const char *cname;
int seq;
+ uint16_t seq_high;
uint32_t timestamp;
uint32_t base_timestamp;
uint32_t cur_timestamp;
diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index f987468f10..66984e6e97 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -43,7 +43,7 @@ static int send_packet(AVFormatContext *ctx, uint8_t parse_code, int info_hdr_si
return AVERROR_INVALIDDATA;
}
- AV_WB16(&rtp_ctx->buf[0], 0); /* extended sequence number */
+ AV_WB16(&rtp_ctx->buf[0], rtp_ctx->seq_high); /* extended sequence number */
AV_WB8 (&rtp_ctx->buf[2], i ? (f ? (0x03) : (0x02)) : 0x00); /* flags: interlaced, second field */
AV_WB8 (&rtp_ctx->buf[3], parse_code);
if (size > 0)