Commit 5e8f97c467 for ffmpeg
commit 5e8f97c467ca203ff01b34db7cee0e3496f4e99b
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Fri Oct 2 18:02:52 2026 +0200
avformat/mov: zero tts_data between tts_count and nb_index_entries in mov_read_trun()
Fixes: read of uninitialized memory
Fixes: uninit.mp4 / gen-uninit.py
Fixes: QcOY0fqViB2h
Found during triage of the security report srZp1wXh4CXQ
Replicated through UnModified FFmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
diff --git a/libavformat/mov.c b/libavformat/mov.c
index 77402ad2ec..3a4a777975 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -6210,7 +6210,6 @@ static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
int64_t prev_dts = AV_NOPTS_VALUE;
int next_frag_index = -1, index_entry_pos;
size_t requested_size;
- size_t old_allocated_size;
AVIndexEntry *new_entries;
MOVFragmentStreamInfo * frag_stream_info;
@@ -6361,7 +6360,6 @@ static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
sti->index_entries= new_entries;
requested_size = (sti->nb_index_entries + entries) * sizeof(*sc->tts_data);
- old_allocated_size = sc->tts_allocated_size;
tts_data = av_fast_realloc(sc->tts_data, &sc->tts_allocated_size,
requested_size);
if (!tts_data)
@@ -6371,8 +6369,9 @@ static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
// In case there were samples without time to sample entries, ensure they get
// zero valued entries. This ensures clips which mix boxes with and
// without time to sample entries don't pickup uninitialized data.
- memset((uint8_t*)(sc->tts_data) + old_allocated_size, 0,
- sc->tts_allocated_size - old_allocated_size);
+ if (sc->tts_count < sti->nb_index_entries)
+ memset(sc->tts_data + sc->tts_count, 0,
+ sizeof(*sc->tts_data) * (sti->nb_index_entries - sc->tts_count));
if (index_entry_pos < sti->nb_index_entries) {
// Make hole in index_entries and tts_data for new samples