Commit 7a4da23a85 for ffmpeg
commit 7a4da23a852b88f2b29187a0c908dc0b911612f9
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 07:07:36 2026 +0200
avformat/rtpenc_vc2hq: Stop on data units shorter than their header
The fix is the one recommended in the report.
Fixes: infinite loop
Fixes: HRhmcrDPRPyf
Fixes: AISLE-2026-0111-00262
Infinite loop Replicated through UnModified FFmpeg with valid Dirac samples
Found-by: Joshua Rogers <joshua.rogers@aisle.com>
diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index 3b7147dfe2..1cff2af9fd 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -119,11 +119,11 @@ void ff_rtp_send_vc2hq(AVFormatContext *ctx, const uint8_t *frame_buf, int frame
uint8_t parse_code;
uint32_t unit_size;
- while (unit < end) {
+ while (end - unit >= DIRAC_DATA_UNIT_HEADER_SIZE) {
parse_code = unit[4];
unit_size = AV_RB32(&unit[5]);
- if (unit_size > end - unit)
+ if (unit_size < DIRAC_DATA_UNIT_HEADER_SIZE || unit_size > end - unit)
break;
switch (parse_code) {
@@ -131,13 +131,11 @@ void ff_rtp_send_vc2hq(AVFormatContext *ctx, const uint8_t *frame_buf, int frame
/* end of sequence */
case DIRAC_PCODE_SEQ_HEADER:
case DIRAC_PCODE_END_SEQ:
- if (unit_size >= DIRAC_DATA_UNIT_HEADER_SIZE)
- send_packet(ctx, parse_code, 0, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, 0, 0, 0);
+ send_packet(ctx, parse_code, 0, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, 0, 0, 0);
break;
/* HQ picture */
case DIRAC_PCODE_PICTURE_HQ:
- if (unit_size >= DIRAC_DATA_UNIT_HEADER_SIZE)
- send_picture(ctx, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, interlaced);
+ send_picture(ctx, unit + DIRAC_DATA_UNIT_HEADER_SIZE, unit_size - DIRAC_DATA_UNIT_HEADER_SIZE, interlaced);
break;
/* parse codes without specification */
case DIRAC_PCODE_AUX: