Commit 33f238c7bd for ffmpeg
commit 33f238c7bd9cbcb3eada4b7b92aa27a27d4bb4a8
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 06:48:27 2026 +0200
avcodec/vvc: Reject slices whose entry point walk does not match num_entry_points
Hardening for ccSUzeWGhBGj
Found-by: Umar Pathan (Umar0x)
diff --git a/libavcodec/vvc/ps.c b/libavcodec/vvc/ps.c
index 4aa1f4767a..d40c8050db 100644
--- a/libavcodec/vvc/ps.c
+++ b/libavcodec/vvc/ps.c
@@ -1472,7 +1472,8 @@ static void sh_partition_constraints(VVCSH *sh, const H266RawSPS *sps, const H26
static int sh_entry_points(VVCSH *sh, const H266RawSPS *sps, const VVCPPS *pps)
{
if (sps->sps_entry_point_offsets_present_flag) {
- for (int i = 1, j = 0; i < sh->num_ctus_in_curr_slice; i++) {
+ int j = 0;
+ for (int i = 1; i < sh->num_ctus_in_curr_slice; i++) {
const int pre_ctb_addr_x = sh->ctb_addr_in_curr_slice[i - 1] % pps->ctb_width;
const int pre_ctb_addr_y = sh->ctb_addr_in_curr_slice[i - 1] / pps->ctb_width;
const int ctb_addr_x = sh->ctb_addr_in_curr_slice[i] % pps->ctb_width;
@@ -1485,6 +1486,8 @@ static int sh_entry_points(VVCSH *sh, const H266RawSPS *sps, const VVCPPS *pps)
sh->entry_point_start_ctu[j++] = i;
}
}
+ if (j != sh->r->num_entry_points)
+ return AVERROR_INVALIDDATA;
}
return 0;