Commit b3f35ef8e5 for ffmpeg
commit b3f35ef8e501c2fc888275b0a9a46209a85ab64c
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Fri Oct 2 19:54:59 2026 +0200
avformat/rtpenc_rfc4175: Split segments longer than 65535 bytes
The Length field of the payload header is 16 bit. A scan line longer
than 65535 bytes that fit into one packet was written with a truncated
length and only that many bytes were copied, while the RTP packet was
sent with the full size. The rest of the payload was uninitialized
memory of the packet buffer or data of a previous packet.
Fixes: read of uninitialized memory
Fixes: RYTTcqy8RYDK
Found during triage of the security report fKcw8qCE1cYW
Replicated through UnModified FFmpeg
diff --git a/libavformat/rtpenc_rfc4175.c b/libavformat/rtpenc_rfc4175.c
index 4fd5fbda9d..764628b27b 100644
--- a/libavformat/rtpenc_rfc4175.c
+++ b/libavformat/rtpenc_rfc4175.c
@@ -87,10 +87,10 @@ void ff_rtp_send_raw_rfc4175(AVFormatContext *s1, const uint8_t *buf, int size,
length = (pixels * pgroup) / xinc;
left -= head_size;
- if (left >= length) {
+ if (left >= length && length <= 0xFFFF) {
next_line = 1;
} else {
- pixels = (left / pgroup) * xinc;
+ pixels = (FFMIN(left, 0xFFFF) / pgroup) * xinc;
length = (pixels * pgroup) / xinc;
next_line = 0;
}