Commit 40922dead0 for ffmpeg

commit 40922dead061fbc9d27c6ec11d3b3b8a41511bbc
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Sun Oct 11 02:03:43 2026 +0200

    avformat/dashenc: Use av_escape() in xmlescape()

    The int based size computation of the open coded escaping overflows for
    strings above about 1.4 GB, av_escape() checks the size.

    Fixes: out of array write
    Fixes: cu2EEgL7QRCV
    Found during reviewt

diff --git a/libavformat/dashenc.c b/libavformat/dashenc.c
index 6b4ab8eeb9..ca8e5401c1 100644
--- a/libavformat/dashenc.c
+++ b/libavformat/dashenc.c
@@ -590,42 +590,10 @@ static void output_segment_list(OutputStream *os, AVIOContext *out, AVFormatCont
 }

 static char *xmlescape(const char *str) {
-    int outlen = strlen(str)*3/2 + 6;
-    char *out = av_realloc(NULL, outlen + 1);
-    int pos = 0;
-    if (!out)
+    char *out;
+    if (av_escape(&out, str, NULL, AV_ESCAPE_MODE_XML,
+                  AV_ESCAPE_FLAG_XML_SINGLE_QUOTES | AV_ESCAPE_FLAG_XML_DOUBLE_QUOTES) < 0)
         return NULL;
-    for (; *str; str++) {
-        if (pos + 6 > outlen) {
-            char *tmp;
-            outlen = 2 * outlen + 6;
-            tmp = av_realloc(out, outlen + 1);
-            if (!tmp) {
-                av_free(out);
-                return NULL;
-            }
-            out = tmp;
-        }
-        if (*str == '&') {
-            memcpy(&out[pos], "&amp;", 5);
-            pos += 5;
-        } else if (*str == '<') {
-            memcpy(&out[pos], "&lt;", 4);
-            pos += 4;
-        } else if (*str == '>') {
-            memcpy(&out[pos], "&gt;", 4);
-            pos += 4;
-        } else if (*str == '\'') {
-            memcpy(&out[pos], "&apos;", 6);
-            pos += 6;
-        } else if (*str == '\"') {
-            memcpy(&out[pos], "&quot;", 6);
-            pos += 6;
-        } else {
-            out[pos++] = *str;
-        }
-    }
-    out[pos] = '\0';
     return out;
 }