Commit ed27bfcbbb for ffmpeg
commit ed27bfcbbbc0872c0195eaf4dd2c0c93b9f1778e
Author: Joshua Rogers <MegaManSec@users.noreply.github.com>
Date: Mon Aug 31 15:31:50 2026 +0200
avutil/avstring: fix infinite loop in av_strireplace with empty search string
av_stristr() returns the input pointer unchanged for an empty needle,
so an empty 'from' argument left pstr never advancing and caused
av_strireplace() to loop forever (and grow the buffer unboundedly if
'to' was non-empty). Return a duplicate of 'str' when 'from' is empty.
Fixes: Timeout
Fixes: q8954W25MJoa
Fixes: AISLE-2026-0100-00001
Found-by: Joshua Rogers <joshua.rogers@aisle.com>
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
diff --git a/libavutil/avstring.c b/libavutil/avstring.c
index 1487297cba..9b81da33bf 100644
--- a/libavutil/avstring.c
+++ b/libavutil/avstring.c
@@ -234,6 +234,9 @@ char *av_strireplace(const char *str, const char *from, const char *to)
size_t tolen = strlen(to), fromlen = strlen(from);
AVBPrint pbuf;
+ if (!fromlen)
+ return av_strdup(str);
+
av_bprint_init(&pbuf, 1, AV_BPRINT_SIZE_UNLIMITED);
while ((pstr2 = av_stristr(pstr, from))) {
av_bprint_append_data(&pbuf, pstr, pstr2 - pstr);