Commit 7a4da23a85 for ffmpeg

commit 7a4da23a852b88f2b29187a0c908dc0b911612f9
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Tue Oct 6 07:07:36 2026 +0200

    avformat/rtpenc_vc2hq: Stop on data units shorter than their header

    The fix is the one recommended in the report.

    Fixes: infinite loop
    Fixes: HRhmcrDPRPyf
    Fixes: AISLE-2026-0111-00262
    Infinite loop Replicated through UnModified FFmpeg with valid Dirac samples
    Found-by: Joshua Rogers <joshua.rogers@aisle.com>

diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index 3b7147dfe2..1cff2af9fd 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -119,11 +119,11 @@ void ff_rtp_send_vc2hq(AVFormatContext *ctx, const uint8_t *frame_buf, int frame
     uint8_t parse_code;
     uint32_t unit_size;

-    while (unit < end) {
+    while (end - unit >= DIRAC_DATA_UNIT_HEADER_SIZE) {
         parse_code = unit[4];
         unit_size = AV_RB32(&unit[5]);

-        if (unit_size > end - unit)
+        if (unit_size < DIRAC_DATA_UNIT_HEADER_SIZE || unit_size > end - unit)
             break;

         switch (parse_code) {
@@ -131,13 +131,11 @@ void ff_rtp_send_vc2hq(AVFormatContext *ctx, const uint8_t *frame_buf, int frame
         /* end of sequence */
         case DIRAC_PCODE_SEQ_HEADER:
         case DIRAC_PCODE_END_SEQ:
-            if (unit_size >= DIRAC_DATA_UNIT_HEADER_SIZE)
-                send_packet(ctx, parse_code, 0, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, 0, 0, 0);
+            send_packet(ctx, parse_code, 0, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, 0, 0, 0);
             break;
         /* HQ picture */
         case DIRAC_PCODE_PICTURE_HQ:
-            if (unit_size >= DIRAC_DATA_UNIT_HEADER_SIZE)
-                send_picture(ctx, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, interlaced);
+            send_picture(ctx, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, interlaced);
             break;
         /* parse codes without specification */
         case DIRAC_PCODE_AUX: