Commit e3f5f17548 for ffmpeg
commit e3f5f17548bc7b773aefd420747863bc35741e37
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Sun Oct 4 23:42:28 2026 +0200
avformat/mov: bound ipco and ipma by the iprp size
This is hardening, no memory safety issue is known to depend on it.
Found-by: OpenAI Security Research
Reported in the security report srZp1wXh4CXQ
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
diff --git a/libavformat/mov.c b/libavformat/mov.c
index 3a4a777975..2eb79c702b 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -9918,9 +9918,10 @@ static int mov_read_iprp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
a.size = avio_rb32(pb);
a.type = avio_rl32(pb);
- if (a.size < 8 || a.type != MKTAG('i','p','c','o'))
+ if (a.size < 8 || a.size > atom.size || a.type != MKTAG('i','p','c','o'))
return AVERROR_INVALIDDATA;
+ atom.size -= a.size;
a.size -= 8;
while (a.size >= 8) {
MOVAtoms *ref = av_dynarray2_add((void**)&atoms, &nb_atoms, sizeof(MOVAtoms), NULL);
@@ -9956,7 +9957,7 @@ static int mov_read_iprp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
a.size = avio_rb32(pb);
a.type = avio_rl32(pb);
- if (a.size < 8 || a.type != MKTAG('i','p','m','a')) {
+ if (a.size < 16 || a.size > atom.size || a.type != MKTAG('i','p','m','a')) {
ret = AVERROR_INVALIDDATA;
goto fail;
}
@@ -9964,12 +9965,14 @@ static int mov_read_iprp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
version = avio_r8(pb);
flags = avio_rb24(pb);
count = avio_rb32(pb);
+ a.size -= 16;
for (int i = 0; i < count; i++) {
int item_id = version ? avio_rb32(pb) : avio_rb16(pb);
int assoc_count = avio_r8(pb);
- if (avio_feof(pb)) {
+ a.size -= (version ? 5 : 3) + assoc_count * (1 + (flags & 1));
+ if (avio_feof(pb) || a.size < 0) {
ret = AVERROR_INVALIDDATA;
goto fail;
}