Commit 793f6013e7 for ffmpeg
commit 793f6013e775827b3b7a5b8845ae9d239949cfa2
Author: Prasanna Dabi <dabi.prasanna@gmail.com>
Date: Sun Oct 11 04:16:39 2026 +0000
avformat/mov: bound infe entries by the iinf size
mov_read_iinf() reads each infe sub-box's declared size directly off
the bitstream with no check against how much of the enclosing iinf
box is actually left, unlike mov_read_iprp() which already bounds its
ipco/ipma entries against the remaining iprp size (e3f5f17, 466ea98).
Track the same kind of running size budget here: subtract the
version/flags/entry_count header from atom.size up front, then
validate each infe_size against what is actually left before trusting
it, mirroring e3f5f17's pattern exactly.
No memory-safety issue is known to depend on this; avio already bounds
reads to the real file length. This is defense-in-depth, closing the
same class of gap the sibling commits above just closed one box over.
Signed-off-by: Prasanna Dabi <dabi.prasanna@gmail.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: James Almer <jamrial@gmail.com>
diff --git a/libavformat/mov.c b/libavformat/mov.c
index d725ef1157..85e28f45f8 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -9627,6 +9627,14 @@ static int mov_read_iinf(MOVContext *c, AVIOContext *pb, MOVAtom atom)
if (entry_count > atom.size)
return AVERROR_INVALIDDATA;
+ /* account for the version/flags/entry_count fields already consumed,
+ * so the per-entry loop below can bound each infe box by what is
+ * actually left in this iinf box, the same way mov_read_iprp() bounds
+ * ipco/ipma entries by the remaining iprp size. */
+ atom.size -= version ? 8 : 6;
+ if (atom.size < 0)
+ return AVERROR_INVALIDDATA;
+
heif_item = av_realloc_array(c->heif_item, FFMAX(entry_count, c->nb_heif_item), sizeof(*c->heif_item));
if (!heif_item)
return AVERROR(ENOMEM);
@@ -9639,12 +9647,17 @@ static int mov_read_iinf(MOVContext *c, AVIOContext *pb, MOVAtom atom)
for (i = 0; i < entry_count; i++) {
MOVAtom infe;
- infe.size = avio_rb32(pb) - 8;
+ infe.size = avio_rb32(pb);
infe.type = avio_rl32(pb);
- if (avio_feof(pb)) {
+ if (avio_feof(pb) || infe.size < 8 || infe.size > atom.size ||
+ infe.type != MKTAG('i','n','f','e')) {
ret = AVERROR_INVALIDDATA;
goto fail;
}
+
+ atom.size -= infe.size;
+ infe.size -= 8;
+
ret = mov_read_infe(c, pb, infe);
if (ret < 0)
goto fail;