Commit 74962818a8 for ffmpeg
commit 74962818a865946bacafaaf97aa015e5baec1f17
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Thu Sep 24 00:54:55 2026 +0200
avfilter/af_dynaudnorm: reallocate the window when a command changes the frame length
Fixes: out of array write
Found during triage/review of the security report jq3f1Nk2lzaK
diff --git a/libavfilter/af_dynaudnorm.c b/libavfilter/af_dynaudnorm.c
index 3e50b32087..98a3bb91e5 100644
--- a/libavfilter/af_dynaudnorm.c
+++ b/libavfilter/af_dynaudnorm.c
@@ -988,7 +988,7 @@ static int process_command(AVFilterContext *ctx, const char *cmd, const char *ar
DynamicAudioNormalizerContext *s = ctx->priv;
AVFilterLink *inlink = ctx->inputs[0];
int prev_filter_size = s->filter_size;
- int ret;
+ int frame_len, ret;
ret = ff_filter_process_command(ctx, cmd, args, res, res_len, flags);
if (ret < 0)
@@ -1005,10 +1005,17 @@ static int process_command(AVFilterContext *ctx, const char *cmd, const char *ar
}
}
- ret = frame_size(inlink->sample_rate, s->frame_len_msec);
- if (ret < 0)
- return ret;
- s->frame_len = ret;
+ frame_len = frame_size(inlink->sample_rate, s->frame_len_msec);
+ if (frame_len < 0)
+ return frame_len;
+ if (frame_len != s->frame_len) {
+ AVFrame *window = ff_get_audio_buffer(ctx->outputs[0], frame_len * 2);
+ if (!window)
+ return AVERROR(ENOMEM);
+ av_frame_free(&s->window);
+ s->window = window;
+ s->frame_len = frame_len;
+ }
s->sample_advance = FFMAX(1, lrint(s->frame_len * (1. - s->overlap)));
if (s->expr_str) {
ret = av_expr_parse(&s->expr, s->expr_str, var_names, NULL, NULL,