Commit 6296187f33 for ffmpeg

commit 6296187f33f3f9729e5fc902bd9104a058cdb33a
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Wed Oct 7 13:18:35 2026 +0200

    avformat/rtpenc_vc2hq: Reject Slice Prefix Bytes and Slice Size Scaler above 65535

    RFC 8450 4.4 limits both to 16 bits, larger values were written
    truncated into the payload header.

    Not a security issue.

    Fixes: 8IKJMRzK0zk6
    Truncated payload header values Replicated through UnModified FFmpeg with RTP capture
    Found during triage of the security report nd3rLqSpKgo5

diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index fdb0b9ad0c..c0bb21d6c0 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -76,6 +76,8 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
                     get_interleaved_ue_golomb(&gc); /* num_y */
     prefix_bytes  = get_interleaved_ue_golomb(&gc);
     size_scaler   = get_interleaved_ue_golomb(&gc);
+    if (prefix_bytes > UINT16_MAX || size_scaler > UINT16_MAX)
+        return AVERROR_INVALIDDATA;
     /* pass the quantization matrices */
     if (get_bits1(&gc)) {
         get_interleaved_ue_golomb(&gc);