Commit 793f6013e7 for ffmpeg

commit 793f6013e775827b3b7a5b8845ae9d239949cfa2
Author: Prasanna Dabi <dabi.prasanna@gmail.com>
Date:   Sun Oct 11 04:16:39 2026 +0000

    avformat/mov: bound infe entries by the iinf size

    mov_read_iinf() reads each infe sub-box's declared size directly off
    the bitstream with no check against how much of the enclosing iinf
    box is actually left, unlike mov_read_iprp() which already bounds its
    ipco/ipma entries against the remaining iprp size (e3f5f17, 466ea98).

    Track the same kind of running size budget here: subtract the
    version/flags/entry_count header from atom.size up front, then
    validate each infe_size against what is actually left before trusting
    it, mirroring e3f5f17's pattern exactly.

    No memory-safety issue is known to depend on this; avio already bounds
    reads to the real file length. This is defense-in-depth, closing the
    same class of gap the sibling commits above just closed one box over.

    Signed-off-by: Prasanna Dabi <dabi.prasanna@gmail.com>
    Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
    Signed-off-by: James Almer <jamrial@gmail.com>

diff --git a/libavformat/mov.c b/libavformat/mov.c
index d725ef1157..85e28f45f8 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -9627,6 +9627,14 @@ static int mov_read_iinf(MOVContext *c, AVIOContext *pb, MOVAtom atom)
     if (entry_count > atom.size)
         return AVERROR_INVALIDDATA;

+    /* account for the version/flags/entry_count fields already consumed,
+     * so the per-entry loop below can bound each infe box by what is
+     * actually left in this iinf box, the same way mov_read_iprp() bounds
+     * ipco/ipma entries by the remaining iprp size. */
+    atom.size -= version ? 8 : 6;
+    if (atom.size < 0)
+        return AVERROR_INVALIDDATA;
+
     heif_item = av_realloc_array(c->heif_item, FFMAX(entry_count, c->nb_heif_item), sizeof(*c->heif_item));
     if (!heif_item)
         return AVERROR(ENOMEM);
@@ -9639,12 +9647,17 @@ static int mov_read_iinf(MOVContext *c, AVIOContext *pb, MOVAtom atom)
     for (i = 0; i < entry_count; i++) {
         MOVAtom infe;

-        infe.size = avio_rb32(pb) - 8;
+        infe.size = avio_rb32(pb);
         infe.type = avio_rl32(pb);
-        if (avio_feof(pb)) {
+        if (avio_feof(pb) || infe.size < 8 || infe.size > atom.size ||
+            infe.type != MKTAG('i','n','f','e')) {
             ret = AVERROR_INVALIDDATA;
             goto fail;
         }
+
+        atom.size -= infe.size;
+        infe.size -= 8;
+
         ret = mov_read_infe(c, pb, infe);
         if (ret < 0)
             goto fail;