Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package ffmpeg-4 for openSUSE:Factory checked in at 2026-08-21 17:01:26 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/ffmpeg-4 (Old) and /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1258 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "ffmpeg-4" Fri Aug 21 17:01:26 2026 rev:99 rq:1372812 version:4.4.8 Changes: -------- --- /work/SRC/openSUSE:Factory/ffmpeg-4/ffmpeg-4.changes 2026-08-04 21:39:34.222980872 +0200 +++ /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1258/ffmpeg-4.changes 2026-08-21 17:02:44.837081543 +0200 @@ -1,0 +2,73 @@ +Wed Aug 14 06:28:33 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-66036.patch: + Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support + dynamic frame sizes. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 05:51:42 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-66036-shim01.patch + Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject + unsupported frame parameter changes. This patch is for facilitate + ffmpeg-CVE-2026-66036.patch. + (CVE-2026-66036, bsc#1272763) + +------------------------------------------------------------------- +Wed Aug 14 05:31:22 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-65706.patch: + Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the + temp row buffer for the widest plane. + (CVE-2026-65706, bsc#1272762) + +------------------------------------------------------------------- +Wed Aug 14 04:56:09 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-65705.patch: + Backport 30a52276 from upstream, avfilter/vf_floodfill: remove + unneeded variables. + (CVE-2026-65705, bsc#1272761) + +------------------------------------------------------------------- +Wed Aug 14 04:31:19 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-65704.patch: + Backport 52f7983f from upstream, avformat/ty: don't let the Series2 + AC3 trim underflow the packet size. + (CVE-2026-65704, bsc#1272760) + +------------------------------------------------------------------- +Wed Aug 14 04:02:11 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-65703.patch: + Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference + frame before reallocating on size change. + (CVE-2026-65703, bsc#1272759) + +------------------------------------------------------------------- +Wed Aug 14 03:46:28 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-64834.patch: + Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF + objects smaller than their header. + (CVE-2026-64834, bsc#1272757) + +------------------------------------------------------------------- +Wed Aug 14 03:33:14 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-64833.patch: + Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS + core_size against the packet size in the HD path. + (CVE-2026-64833, bsc#1272755) + +------------------------------------------------------------------- +Wed Aug 14 03:28:13 UTC 2026 - Cliff Zhao <[email protected]> + +- Add ffmpeg-4-CVE-2026-58049.patch: + Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit + DLTA accesses stay within the row. + (CVE-2026-58049, bsc#1269550) + +------------------------------------------------------------------- New: ---- ffmpeg-4-CVE-2026-58049.patch ffmpeg-4-CVE-2026-64833.patch ffmpeg-4-CVE-2026-64834.patch ffmpeg-4-CVE-2026-65703.patch ffmpeg-4-CVE-2026-65704.patch ffmpeg-4-CVE-2026-65705.patch ffmpeg-4-CVE-2026-65706.patch ffmpeg-4-CVE-2026-66036-shim01.patch ffmpeg-4-CVE-2026-66036.patch ----------(New B)---------- New: - Add ffmpeg-4-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit New: - Add ffmpeg-4-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS New: - Add ffmpeg-4-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF New: - Add ffmpeg-4-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference New: - Add ffmpeg-4-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 New: - Add ffmpeg-4-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove New: - Add ffmpeg-4-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the New: - Add ffmpeg-4-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject New: - Add ffmpeg-4-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ ffmpeg-4.spec ++++++ --- /var/tmp/diff_new_pack.oyvyDY/_old 2026-08-21 17:02:46.316133909 +0200 +++ /var/tmp/diff_new_pack.oyvyDY/_new 2026-08-21 17:02:46.322134121 +0200 @@ -155,6 +155,15 @@ Patch46: ffmpeg-4-CVE-2026-64830.patch Patch47: ffmpeg-4-CVE-2026-66038.patch Patch48: ffmpeg-4-CVE-2026-66039.patch +Patch49: ffmpeg-4-CVE-2026-58049.patch +Patch50: ffmpeg-4-CVE-2026-64833.patch +Patch51: ffmpeg-4-CVE-2026-64834.patch +Patch52: ffmpeg-4-CVE-2026-65703.patch +Patch53: ffmpeg-4-CVE-2026-65704.patch +Patch54: ffmpeg-4-CVE-2026-65705.patch +Patch55: ffmpeg-4-CVE-2026-65706.patch +Patch56: ffmpeg-4-CVE-2026-66036-shim01.patch +Patch57: ffmpeg-4-CVE-2026-66036.patch BuildRequires: ladspa-devel BuildRequires: libgsm-devel BuildRequires: libmp3lame-devel ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.oyvyDY/_old 2026-08-21 17:02:46.396136741 +0200 +++ /var/tmp/diff_new_pack.oyvyDY/_new 2026-08-21 17:02:46.401136918 +0200 @@ -1,5 +1,5 @@ -mtime: 1785803606 -commit: 7735673b58953246683a52fc3da8206c86599ba76e135b733f538331877a6111 +mtime: 1787302634 +commit: 7d6dcca0e998a1009e33e1e77b555fbcd225c40524e161cb13901767244b56d7 url: https://src.opensuse.org/jengelh/ffmpeg-4 revision: master ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-08-21 10:57:14.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ ffmpeg-4-CVE-2026-58049.patch ++++++ >From f8d7795dcca36a4dd412e89cbd83e3dfec1e0d81 Mon Sep 17 00:00:00 2001 From: Umar Pathan <[email protected]> Date: Sun, 28 Jun 2026 23:02:52 +0200 Subject: [PATCH] avcodec/rasc: Check that 32-bit DLTA accesses stay within the row Found-by: bikini (github.com/bikini/exploitarium) Fixes: out of array access Fixes: rowspill_128x1.avi / gen_rowspill_avi.py Fixes: xGV79bIb7uAJ (cherry picked from commit 11ff18a6c80187405fc492f9bb07ba9f2f663f76) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rasc.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/libavcodec/rasc.c b/libavcodec/rasc.c index 5f956a9b2c..d784a44063 100644 --- a/libavcodec/rasc.c +++ b/libavcodec/rasc.c @@ -320,6 +320,11 @@ static int decode_move(AVCodecContext *avctx, return 0; } +static inline int dlta_room(unsigned cx, unsigned w, unsigned bpp, unsigned need) +{ + return cx + need <= w * bpp; +} + #define NEXT_LINE \ if (cx >= w * s->bpp) { \ cx = 0; \ @@ -418,6 +423,8 @@ static int decode_dlta(AVCodecContext *avctx, case 4: fill = bytestream2_get_byte(&dc); while (len > 0 && cy > 0) { + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx++; @@ -427,6 +434,8 @@ static int decode_dlta(AVCodecContext *avctx, case 7: fill = bytestream2_get_le32(&dc); while (len > 0 && cy > 0) { + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx += 4; @@ -443,6 +452,8 @@ static int decode_dlta(AVCodecContext *avctx, while (len > 0 && cy > 0) { unsigned v0, v1; + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; v0 = AV_RL32(b2 + cx); v1 = AV_RL32(b1 + cx); AV_WL32(b2 + cx, v1); @@ -454,6 +465,8 @@ static int decode_dlta(AVCodecContext *avctx, case 13: while (len > 0 && cy > 0) { fill = bytestream2_get_le32(&dc); + if (!dlta_room(cx, w, s->bpp, 4)) + return AVERROR_INVALIDDATA; AV_WL32(b1 + cx, AV_RL32(b2 + cx)); AV_WL32(b2 + cx, fill); cx += 4; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-64833.patch ++++++ >From 385ac2fadcb4394ec4f65e5c4d3d24003e090f36 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Tue, 30 Jun 2026 00:11:50 +0200 Subject: [PATCH] avformat/spdifenc: bound DTS core_size against the packet size in the HD path Fixes: out of array read Fixes: yBSax492UIB9 Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 6f80e2765492700622596af720534cef33dd31b4) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/spdifenc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c index ab3f73da0d..16eebda01c 100644 --- a/libavformat/spdifenc.c +++ b/libavformat/spdifenc.c @@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size, * (dtshd_fallback == 0) */ ctx->dtshd_skip = 1; } - if (ctx->dtshd_skip && core_size) { + if (ctx->dtshd_skip && core_size && core_size <= pkt->size) { pkt_size = core_size; if (ctx->dtshd_fallback >= 0) --ctx->dtshd_skip; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-64834.patch ++++++ >From 3c441711a343ccf50196c70a3f0b554b52f8d9de Mon Sep 17 00:00:00 2001 From: Pavel Kohout <[email protected]> Date: Tue, 30 Jun 2026 21:55:16 +0200 Subject: [PATCH] avformat/rtpdec_asf: reject ASF objects smaller than their header Fixes: infinite loop Fixes: MzWwJdpZF2Ls Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet parsing.) Found-by: Pavel Kohout (Aisle Research) Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit 11d5f475be95d22d5f0692220cc772b116abc632) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/rtpdec_asf.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c index b3b346f3cc..f7fa69e27f 100644 --- a/libavformat/rtpdec_asf.c +++ b/libavformat/rtpdec_asf.c @@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len) uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid)); int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2; if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) { + if (chunksize < sizeof(ff_asf_guid) + 8) + return -1; if (chunksize > end - p) return -1; p += chunksize; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-65703.patch ++++++ >From 3b85fbe89025ea696988488358dfde41a09c53c5 Mon Sep 17 00:00:00 2001 From: Cloud-LHY <[email protected]> Date: Fri, 10 Jul 2026 04:07:04 +0200 Subject: [PATCH] avcodec/tdsc: unref the reference frame before reallocating on size change Fixes: out of array access Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py Fixes: p9xG4xGf9P7H Fixes: HQL7a1WgTdHZ Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS Found-by: Adrian Junge (vurlo) (cherry picked from commit fd3ee52fab34d98a95b787d0b5ff45685766200c) Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/tdsc.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c index ca9dd0f0a6..102b4ae966 100644 --- a/libavcodec/tdsc.c +++ b/libavcodec/tdsc.c @@ -485,11 +485,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int number_tiles) return ret; init_refframe = 1; } - ctx->refframe->width = ctx->width = w; - ctx->refframe->height = ctx->height = h; + ctx->width = w; + ctx->height = h; /* Allocate the reference frame if not already done or on size change */ if (init_refframe) { + av_frame_unref(ctx->refframe); + ctx->refframe->format = avctx->pix_fmt; + ctx->refframe->width = w; + ctx->refframe->height = h; ret = av_frame_get_buffer(ctx->refframe, 0); if (ret < 0) return ret; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-65704.patch ++++++ >From 52f7983f15678c8a6065327760d7b6eb1c9c84ed Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Fri, 10 Jul 2026 04:07:35 +0200 Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the packet size Fixes: negative-size-param Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py Fixes: g0qeE6KvrjZi Found-by: Adrian Junge (vurlo) (cherry picked from commit de771bd52774a52d45b0e2c82e56995a1ef40df7) Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/ty.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/ty.c b/libavformat/ty.c index 9be027fcca..842d97038c 100644 --- a/libavformat/ty.c +++ b/libavformat/ty.c @@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt) if (ty->audio_type == TIVO_AUDIO_AC3 && ty->tivo_series == TIVO_SERIES2) { if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) { - pkt->size -= 2; + pkt->size -= FFMIN(pkt->size, 2); ty->ac3_pkt_size = 0; } else { ty->ac3_pkt_size += pkt->size; -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-65705.patch ++++++ >From 30a52276f9dff60fe732d8bb8d463e587ff69c94 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 03:27:47 +0200 Subject: [PATCH] avfilter/vf_floodfill: remove unneeded variables Signed-off-by: Michael Niedermayer <[email protected]> (cherry picked from commit f186c50cf53aec20e9a29059cb22ca3f2d59201c) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_floodfill.c | 35 ++++++++++++++++------------------- 1 file changed, 16 insertions(+), 19 deletions(-) diff -a a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c --- a/libavfilter/vf_floodfill.c +++ b/libavfilter/vf_floodfill.c @@ -39,7 +39,6 @@ typedef struct FloodfillContext { int d[4]; int nb_planes; - int back, front; Points *points; int (*is_same)(AVFrame *frame, int x, int y, @@ -270,7 +269,6 @@ static int config_input(AVFilterLink *in } } - s->front = s->back = 0; s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points)); if (!s->points) return AVERROR(ENOMEM); @@ -293,6 +291,7 @@ static int filter_frame(AVFilterLink *li const int w = frame->width; const int h = frame->height; int i, ret; + int front = 0; if (is_inside(s->x, s->y, w, h)) { s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3); @@ -310,42 +309,42 @@ static int filter_frame(AVFilterLink *li goto end; if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) { - s->points[s->front].x = s->x; - s->points[s->front].y = s->y; - s->front++; + s->points[front].x = s->x; + s->points[front].y = s->y; + front++; } if (ret = av_frame_make_writable(frame)) return ret; - while (s->front > s->back) { + while (front > 0) { int x, y; - s->front--; - x = s->points[s->front].x; - y = s->points[s->front].y; + front--; + x = s->points[front].x; + y = s->points[front].y; if (s->is_same(frame, x, y, s0, s1, s2, s3)) { s->set_pixel(frame, x, y, d0, d1, d2, d3); if (is_inside(x + 1, y, w, h)) { - s->points[s->front] .x = x + 1; - s->points[s->front++].y = y; + s->points[front] .x = x + 1; + s->points[front++].y = y; } if (is_inside(x - 1, y, w, h)) { - s->points[s->front] .x = x - 1; - s->points[s->front++].y = y; + s->points[front] .x = x - 1; + s->points[front++].y = y; } if (is_inside(x, y + 1, w, h)) { - s->points[s->front] .x = x; - s->points[s->front++].y = y + 1; + s->points[front] .x = x; + s->points[front++].y = y + 1; } if (is_inside(x, y - 1, w, h)) { - s->points[s->front] .x = x; - s->points[s->front++].y = y - 1; + s->points[front] .x = x; + s->points[front++].y = y - 1; } } } ++++++ ffmpeg-4-CVE-2026-65706.patch ++++++ >From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sat, 11 Jul 2026 16:46:39 +0200 Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest plane Fixes: out of array access Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py Fixes: VRAXYvKtmKa8 Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_swaprect.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c index 5d93f51c30..fe007ee5e7 100644 --- a/libavfilter/vf_swaprect.c +++ b/libavfilter/vf_swaprect.c @@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink) { AVFilterContext *ctx = inlink->dst; SwapRectContext *s = ctx->priv; + int size = 0; if (!s->w || !s->h || !s->x1 || !s->y1 || @@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink) av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc); s->nb_planes = av_pix_fmt_count_planes(inlink->format); - s->temp = av_malloc_array(inlink->w, s->pixsteps[0]); + for (int p = 0; p < s->nb_planes; p++) { + int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0; + int width = AV_CEIL_RSHIFT(inlink->w, shift); + + if (width > INT_MAX / s->pixsteps[p]) + return AVERROR(EINVAL); + size = FFMAX(size, width * s->pixsteps[p]); + } + + s->temp = av_malloc(size); if (!s->temp) return AVERROR(ENOMEM); -- 2.49.0 ++++++ ffmpeg-4-CVE-2026-66036-shim01.patch ++++++ >From e3d0c719fddd259709c8e275942ab56af3afc35d Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 12 Jul 2026 13:05:07 +0200 Subject: [PATCH] avfilter/vf_hqdn3d: reject unsupported frame parameter changes Fixes: out of array access Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py Fixes: wWDsy2oDvMuR Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++--------- libavfilter/vf_hqdn3d.h | 2 ++ 2 files changed, 27 insertions(+), 9 deletions(-) diff -a a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c --- a/libavfilter/vf_hqdn3d.c +++ b/libavfilter/vf_hqdn3d.c @@ -164,12 +164,8 @@ static int denoise_depth(HQDN3DContext * case 14: ret = denoise_depth(__VA_ARGS__, 14); break; \ case 16: ret = denoise_depth(__VA_ARGS__, 16); break; \ } \ - if (ret < 0) { \ - av_frame_free(&out); \ - if (!direct) \ - av_frame_free(&in); \ + if (ret < 0) \ return ret; \ - } \ } while (0) static void precalc_coefs(double dist25, int depth, int16_t *ct) @@ -288,12 +284,15 @@ static int config_input(AVFilterLink *in if (ARCH_X86) ff_hqdn3d_init_x86(s); + s->format = inlink->format; + s->width = inlink->w; + s->height = inlink->h; + return 0; } typedef struct ThreadData { AVFrame *in, *out; - int direct; } ThreadData; static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs) @@ -302,7 +301,6 @@ static int do_denoise(AVFilterContext *c const ThreadData *td = data; AVFrame *out = td->out; AVFrame *in = td->in; - int direct = td->direct; denoise(s, in->data[job_nr], out->data[job_nr], s->line[job_nr], &s->frame_prev[job_nr], @@ -319,10 +317,21 @@ static int filter_frame(AVFilterLink *in { AVFilterContext *ctx = inlink->dst; AVFilterLink *outlink = ctx->outputs[0]; + HQDN3DContext *s = ctx->priv; AVFrame *out; int direct = av_frame_is_writable(in) && !ctx->is_disabled; ThreadData td; + int ret[3]; + + if (in->format != s->format || + in->width != s->width || + in->height != s->height) { + av_log(ctx, AV_LOG_ERROR, + "Frame size or format changed without filter graph reinitialization\n"); + av_frame_free(&in); + return AVERROR(EINVAL); + } if (direct) { out = in; @@ -338,9 +347,16 @@ static int filter_frame(AVFilterLink *in td.in = in; td.out = out; - td.direct = direct; /* one thread per plane */ - ctx->internal->execute(ctx, do_denoise, &td, NULL, 3); + ctx->internal->execute(ctx, do_denoise, &td, ret, 3); + for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) { + if (ret[i] < 0) { + av_frame_free(&out); + if (!direct) + av_frame_free(&in); + return ret[i]; + } + } if (ctx->is_disabled) { av_frame_free(&out); diff -a a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h --- a/libavfilter/vf_hqdn3d.h +++ b/libavfilter/vf_hqdn3d.h @@ -36,6 +36,8 @@ typedef struct HQDN3DContext { double strength[4]; int hsub, vsub; int depth; + int width, height; + enum AVPixelFormat format; void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal); } HQDN3DContext; ++++++ ffmpeg-4-CVE-2026-66036.patch ++++++ >From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sat, 11 Jul 2026 16:46:39 +0200 Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest plane Fixes: out of array access Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py Fixes: VRAXYvKtmKa8 Found-by: Adrian Junge (vurlo) <[email protected]> (cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527) Signed-off-by: Michael Niedermayer <[email protected]> --- libavfilter/vf_swaprect.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff a/libavfilter/avfilter.c b/libavfilter/avfilter.c --- a/libavfilter/avfilter.c +++ b/libavfilter/avfilter.c @@ -1104,7 +1104,8 @@ int ff_filter_frame(AVFilterLink *link, strcmp(link->dst->filter->name, "format") && strcmp(link->dst->filter->name, "idet") && strcmp(link->dst->filter->name, "null") && - strcmp(link->dst->filter->name, "scale")) { + strcmp(link->dst->filter->name, "scale") && + strcmp(link->dst->filter->name, "hqdn3d")) { av_assert1(frame->format == link->format); av_assert1(frame->width == link->w); av_assert1(frame->height == link->h); diff a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c --- a/libavfilter/vf_hqdn3d.c +++ b/libavfilter/vf_hqdn3d.c @@ -322,21 +322,28 @@ static int filter_frame(AVFilterLink *in AVFrame *out; int direct = av_frame_is_writable(in) && !ctx->is_disabled; ThreadData td; - int ret[3]; + int err, ret[3]; - if (in->format != s->format || - in->width != s->width || - in->height != s->height) { - av_log(ctx, AV_LOG_ERROR, - "Frame size or format changed without filter graph reinitialization\n"); + if (in->format != s->format) { av_frame_free(&in); return AVERROR(EINVAL); } + if (in->width != s->width || in->height != s->height) { + inlink->w = in->width; + inlink->h = in->height; + if ((err = config_input(inlink)) < 0) { + av_frame_free(&in); + return err; + } + outlink->w = in->width; + outlink->h = in->height; + } + if (direct) { out = in; } else { - out = ff_get_video_buffer(outlink, outlink->w, outlink->h); + out = ff_get_video_buffer(outlink, in->width, in->height); if (!out) { av_frame_free(&in); return AVERROR(ENOMEM);
