Commit 819378bdda for ffmpeg
commit 819378bdda9a5d57c6fefa7836542f1e9ec8f55b
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 07:16:13 2026 +0200
avformat/sierravmd: Do not return the unwritten record space of Indeo3 frames
Allocating only frame_size bytes for Indeo3 frames was suggested in the report.
Fixes: use of uninitialized memory
Fixes: TlRax2lAwSba
Fixes: AISLE-2026-0111-00077
Use of uninitialized memory Replicated through UnModified FFmpeg (ffprobe) with Valgrind
Found-by: Joshua Rogers <joshua.rogers@aisle.com>
diff --git a/libavformat/sierravmd.c b/libavformat/sierravmd.c
index a86b0a1603..0b24d3f45e 100644
--- a/libavformat/sierravmd.c
+++ b/libavformat/sierravmd.c
@@ -272,7 +272,7 @@ static int vmd_read_packet(AVFormatContext *s,
{
VmdDemuxContext *vmd = s->priv_data;
AVIOContext *pb = s->pb;
- int ret = 0;
+ int ret = 0, record_size;
vmd_frame *frame;
if (vmd->current_frame >= vmd->frame_count)
@@ -284,16 +284,13 @@ static int vmd_read_packet(AVFormatContext *s,
if(ffio_limit(pb, frame->frame_size) != frame->frame_size)
return AVERROR_INVALIDDATA;
- ret = av_new_packet(pkt, frame->frame_size + BYTES_PER_FRAME_RECORD);
+ record_size = vmd->is_indeo3 && frame->frame_record[0] == 0x02 ? 0 : BYTES_PER_FRAME_RECORD;
+ ret = av_new_packet(pkt, frame->frame_size + record_size);
if (ret < 0)
return ret;
pkt->pos= avio_tell(pb);
- memcpy(pkt->data, frame->frame_record, BYTES_PER_FRAME_RECORD);
- if(vmd->is_indeo3 && frame->frame_record[0] == 0x02)
- ret = ffio_read_size(pb, pkt->data, frame->frame_size);
- else
- ret = ffio_read_size(pb, pkt->data + BYTES_PER_FRAME_RECORD,
- frame->frame_size);
+ memcpy(pkt->data, frame->frame_record, record_size);
+ ret = ffio_read_size(pb, pkt->data + record_size, frame->frame_size);
pkt->stream_index = frame->stream_index;
pkt->pts = frame->pts;