Commit edadf711a9 for ffmpeg
commit edadf711a9d0210c38f9fc9f438624e3c374b3ed
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 16:22:51 2026 +0200
avformat/flacdec: do not feed the parser after the EOF flush in flac_read_timestamp()
Once a read failed, only flush the parser until it returns no more data.
Found during triage of the security report QjW951nk93s9
Fixes: QjW951nk93s9
diff --git a/libavformat/flacdec.c b/libavformat/flacdec.c
index e80b49307d..8d907bdc30 100644
--- a/libavformat/flacdec.c
+++ b/libavformat/flacdec.c
@@ -284,7 +284,7 @@ av_unused static int64_t flac_read_timestamp(AVFormatContext *s, int stream_inde
AVPacket *const pkt = si->parse_pkt;
AVStream *st = s->streams[stream_index];
AVCodecParserContext *parser;
- int ret;
+ int ret = 0;
int64_t pts = AV_NOPTS_VALUE;
if (avio_seek(s->pb, *ppos, SEEK_SET) < 0)
@@ -309,7 +309,8 @@ av_unused static int64_t flac_read_timestamp(AVFormatContext *s, int stream_inde
uint8_t *data;
int size;
- ret = ff_raw_read_partial_packet(s, pkt);
+ if (ret >= 0 || ret == AVERROR(EAGAIN))
+ ret = ff_raw_read_partial_packet(s, pkt);
if (ret < 0){
if (ret == AVERROR(EAGAIN))
continue;