Commit 5e8f97c467 for ffmpeg

commit 5e8f97c467ca203ff01b34db7cee0e3496f4e99b
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Fri Oct 2 18:02:52 2026 +0200

    avformat/mov: zero tts_data between tts_count and nb_index_entries in mov_read_trun()

    Fixes: read of uninitialized memory
    Fixes: uninit.mp4 / gen-uninit.py
    Fixes: QcOY0fqViB2h
    Found during triage of the security report srZp1wXh4CXQ
    Replicated through UnModified FFmpeg

    Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>

diff --git a/libavformat/mov.c b/libavformat/mov.c
index 77402ad2ec..3a4a777975 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -6210,7 +6210,6 @@ static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
     int64_t prev_dts = AV_NOPTS_VALUE;
     int next_frag_index = -1, index_entry_pos;
     size_t requested_size;
-    size_t old_allocated_size;
     AVIndexEntry *new_entries;
     MOVFragmentStreamInfo * frag_stream_info;

@@ -6361,7 +6360,6 @@ static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
     sti->index_entries= new_entries;

     requested_size = (sti->nb_index_entries + entries) * sizeof(*sc->tts_data);
-    old_allocated_size = sc->tts_allocated_size;
     tts_data = av_fast_realloc(sc->tts_data, &sc->tts_allocated_size,
                                 requested_size);
     if (!tts_data)
@@ -6371,8 +6369,9 @@ static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
     // In case there were samples without time to sample entries, ensure they get
     // zero valued entries. This ensures clips which mix boxes with and
     // without time to sample entries don't pickup uninitialized data.
-    memset((uint8_t*)(sc->tts_data) + old_allocated_size, 0,
-           sc->tts_allocated_size - old_allocated_size);
+    if (sc->tts_count < sti->nb_index_entries)
+        memset(sc->tts_data + sc->tts_count, 0,
+               sizeof(*sc->tts_data) * (sti->nb_index_entries - sc->tts_count));

     if (index_entry_pos < sti->nb_index_entries) {
         // Make hole in index_entries and tts_data for new samples