Commit 6296187f33 for ffmpeg
commit 6296187f33f3f9729e5fc902bd9104a058cdb33a
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Wed Oct 7 13:18:35 2026 +0200
avformat/rtpenc_vc2hq: Reject Slice Prefix Bytes and Slice Size Scaler above 65535
RFC 8450 4.4 limits both to 16 bits, larger values were written
truncated into the payload header.
Not a security issue.
Fixes: 8IKJMRzK0zk6
Truncated payload header values Replicated through UnModified FFmpeg with RTP capture
Found during triage of the security report nd3rLqSpKgo5
diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index fdb0b9ad0c..c0bb21d6c0 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -76,6 +76,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
get_interleaved_ue_golomb(&gc); /* num_y */
prefix_bytes = get_interleaved_ue_golomb(&gc);
size_scaler = get_interleaved_ue_golomb(&gc);
+ if (prefix_bytes > UINT16_MAX || size_scaler > UINT16_MAX)
+ return AVERROR_INVALIDDATA;
/* pass the quantization matrices */
if (get_bits1(&gc)) {
get_interleaved_ue_golomb(&gc);