Commit aeadaca2ab for ffmpeg
commit aeadaca2ab90b78ce9199c45973cace4b619c5d3
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Thu Oct 8 16:18:44 2026 +0200
avformat/vpk: Compute the last block size per channel
The last block size was computed from the samples left after the full
blocks, for all channels together. When the duration was a multiple of
the samples per block it was 0 and the last block was returned as an
empty packet, otherwise it could be a size that is not a multiple of the
channel count, and the end of the packet was not written.
The empty last block was found during triage of the security report.
Fixes: use of uninitialized memory
Fixes: ApyrsACJSltE
Fixes: AISLE-2026-0111-00564
Use of uninitialized memory Replicated through UnModified FFmpeg with Valgrind
Empty last packet Replicated through UnModified FFmpeg
Found-by: Joshua Rogers <joshua.rogers@aisle.com>
diff --git a/libavformat/vpk.c b/libavformat/vpk.c
index 172e45d7da..55ee760711 100644
--- a/libavformat/vpk.c
+++ b/libavformat/vpk.c
@@ -68,7 +68,7 @@ static int vpk_read_header(AVFormatContext *s)
if (samples_per_block <= 0)
return AVERROR_INVALIDDATA;
vpk->block_count = (st->duration + (samples_per_block - 1)) / samples_per_block;
- vpk->last_block_size = (st->duration % samples_per_block) * 16 * st->codecpar->ch_layout.nb_channels / 28;
+ vpk->last_block_size = (st->duration - ((int64_t)vpk->block_count - 1) * samples_per_block) * 16 / 28 * st->codecpar->ch_layout.nb_channels;
if (offset < avio_tell(s->pb))
return AVERROR_INVALIDDATA;