Commit b3f35ef8e5 for ffmpeg

commit b3f35ef8e501c2fc888275b0a9a46209a85ab64c
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Fri Oct 2 19:54:59 2026 +0200

    avformat/rtpenc_rfc4175: Split segments longer than 65535 bytes

    The Length field of the payload header is 16 bit. A scan line longer
    than 65535 bytes that fit into one packet was written with a truncated
    length and only that many bytes were copied, while the RTP packet was
    sent with the full size. The rest of the payload was uninitialized
    memory of the packet buffer or data of a previous packet.

    Fixes: read of uninitialized memory
    Fixes: RYTTcqy8RYDK
    Found during triage of the security report fKcw8qCE1cYW
    Replicated through UnModified FFmpeg

diff --git a/libavformat/rtpenc_rfc4175.c b/libavformat/rtpenc_rfc4175.c
index 4fd5fbda9d..764628b27b 100644
--- a/libavformat/rtpenc_rfc4175.c
+++ b/libavformat/rtpenc_rfc4175.c
@@ -87,10 +87,10 @@ void ff_rtp_send_raw_rfc4175(AVFormatContext *s1, const uint8_t *buf, int size,
             length = (pixels * pgroup) / xinc;

             left -= head_size;
-            if (left >= length) {
+            if (left >= length && length <= 0xFFFF) {
                 next_line = 1;
             } else {
-                pixels = (left / pgroup) * xinc;
+                pixels = (FFMIN(left, 0xFFFF) / pgroup) * xinc;
                 length = (pixels * pgroup) / xinc;
                 next_line = 0;
             }