Commit 5647739ddd for ffmpeg
commit 5647739dddb2679ebfe488d6745f0fa1f405bc5d
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Fri Oct 2 17:53:35 2026 +0200
avformat/mov: keep frag_index.current on its fragment in update_frag_index()
The assertion failure was found during triage of the security report
srZp1wXh4CXQ.
Fixes: out of array access
Fixes: Assertion index_entry_pos <= sti->nb_index_entries failed
Fixes: crash.mp4 / make-crash.py
Fixes: variant-assert.mp4 / make-variant-assert.py
Fixes: srZp1wXh4CXQ
Found-by: OpenAI Security Research
Replicated through UnModified FFmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
diff --git a/libavformat/mov.c b/libavformat/mov.c
index e3e0100e11..77402ad2ec 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -1917,6 +1917,8 @@ static int update_frag_index(MOVContext *c, int64_t offset)
if (index < c->frag_index.nb_items)
memmove(c->frag_index.item + index + 1, c->frag_index.item + index,
(c->frag_index.nb_items - index) * sizeof(*c->frag_index.item));
+ if (index <= c->frag_index.current)
+ c->frag_index.current++;
item = &c->frag_index.item[index];
item->headers_read = 0;