Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package ffmpeg-4 for openSUSE:Factory 
checked in at 2026-08-21 17:01:26
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/ffmpeg-4 (Old)
 and      /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1258 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "ffmpeg-4"

Fri Aug 21 17:01:26 2026 rev:99 rq:1372812 version:4.4.8

Changes:
--------
--- /work/SRC/openSUSE:Factory/ffmpeg-4/ffmpeg-4.changes        2026-08-04 
21:39:34.222980872 +0200
+++ /work/SRC/openSUSE:Factory/.ffmpeg-4.new.1258/ffmpeg-4.changes      
2026-08-21 17:02:44.837081543 +0200
@@ -1,0 +2,73 @@
+Wed Aug 14 06:28:33 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-66036.patch:
+  Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support
+  dynamic frame sizes.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 05:51:42 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-66036-shim01.patch
+  Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject
+  unsupported frame parameter changes. This patch is for facilitate
+  ffmpeg-CVE-2026-66036.patch.
+  (CVE-2026-66036, bsc#1272763)
+
+-------------------------------------------------------------------
+Wed Aug 14 05:31:22 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-65706.patch:
+  Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the
+  temp row buffer for the widest plane.
+  (CVE-2026-65706, bsc#1272762)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:56:09 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-65705.patch:
+  Backport 30a52276 from upstream, avfilter/vf_floodfill: remove
+  unneeded variables.
+  (CVE-2026-65705, bsc#1272761)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:31:19 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-65704.patch:
+  Backport 52f7983f from upstream, avformat/ty: don't let the Series2
+  AC3 trim underflow the packet size.
+  (CVE-2026-65704, bsc#1272760)
+
+-------------------------------------------------------------------
+Wed Aug 14 04:02:11 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-65703.patch:
+  Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference
+  frame before reallocating on size change.
+  (CVE-2026-65703, bsc#1272759)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:46:28 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-64834.patch:
+  Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF
+  objects smaller than their header.
+  (CVE-2026-64834, bsc#1272757)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:33:14 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-64833.patch:
+  Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS
+  core_size against the packet size in the HD path.
+  (CVE-2026-64833, bsc#1272755)
+
+-------------------------------------------------------------------
+Wed Aug 14 03:28:13 UTC 2026 - Cliff Zhao <[email protected]>
+
+- Add ffmpeg-4-CVE-2026-58049.patch:
+  Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit
+  DLTA accesses stay within the row.
+  (CVE-2026-58049, bsc#1269550)
+
+-------------------------------------------------------------------

New:
----
  ffmpeg-4-CVE-2026-58049.patch
  ffmpeg-4-CVE-2026-64833.patch
  ffmpeg-4-CVE-2026-64834.patch
  ffmpeg-4-CVE-2026-65703.patch
  ffmpeg-4-CVE-2026-65704.patch
  ffmpeg-4-CVE-2026-65705.patch
  ffmpeg-4-CVE-2026-65706.patch
  ffmpeg-4-CVE-2026-66036-shim01.patch
  ffmpeg-4-CVE-2026-66036.patch

----------(New B)----------
  New:
- Add ffmpeg-4-CVE-2026-58049.patch:
  Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit
  New:
- Add ffmpeg-4-CVE-2026-64833.patch:
  Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS
  New:
- Add ffmpeg-4-CVE-2026-64834.patch:
  Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF
  New:
- Add ffmpeg-4-CVE-2026-65703.patch:
  Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference
  New:
- Add ffmpeg-4-CVE-2026-65704.patch:
  Backport 52f7983f from upstream, avformat/ty: don't let the Series2
  New:
- Add ffmpeg-4-CVE-2026-65705.patch:
  Backport 30a52276 from upstream, avfilter/vf_floodfill: remove
  New:
- Add ffmpeg-4-CVE-2026-65706.patch:
  Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the
  New:
- Add ffmpeg-4-CVE-2026-66036-shim01.patch
  Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject
  New:
- Add ffmpeg-4-CVE-2026-66036.patch:
  Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ ffmpeg-4.spec ++++++
--- /var/tmp/diff_new_pack.oyvyDY/_old  2026-08-21 17:02:46.316133909 +0200
+++ /var/tmp/diff_new_pack.oyvyDY/_new  2026-08-21 17:02:46.322134121 +0200
@@ -155,6 +155,15 @@
 Patch46:        ffmpeg-4-CVE-2026-64830.patch
 Patch47:        ffmpeg-4-CVE-2026-66038.patch
 Patch48:        ffmpeg-4-CVE-2026-66039.patch
+Patch49:        ffmpeg-4-CVE-2026-58049.patch
+Patch50:        ffmpeg-4-CVE-2026-64833.patch
+Patch51:        ffmpeg-4-CVE-2026-64834.patch
+Patch52:        ffmpeg-4-CVE-2026-65703.patch
+Patch53:        ffmpeg-4-CVE-2026-65704.patch
+Patch54:        ffmpeg-4-CVE-2026-65705.patch
+Patch55:        ffmpeg-4-CVE-2026-65706.patch
+Patch56:        ffmpeg-4-CVE-2026-66036-shim01.patch
+Patch57:        ffmpeg-4-CVE-2026-66036.patch
 BuildRequires:  ladspa-devel
 BuildRequires:  libgsm-devel
 BuildRequires:  libmp3lame-devel

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.oyvyDY/_old  2026-08-21 17:02:46.396136741 +0200
+++ /var/tmp/diff_new_pack.oyvyDY/_new  2026-08-21 17:02:46.401136918 +0200
@@ -1,5 +1,5 @@
-mtime: 1785803606
-commit: 7735673b58953246683a52fc3da8206c86599ba76e135b733f538331877a6111
+mtime: 1787302634
+commit: 7d6dcca0e998a1009e33e1e77b555fbcd225c40524e161cb13901767244b56d7
 url: https://src.opensuse.org/jengelh/ffmpeg-4
 revision: master
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-08-21 10:57:14.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ ffmpeg-4-CVE-2026-58049.patch ++++++
>From f8d7795dcca36a4dd412e89cbd83e3dfec1e0d81 Mon Sep 17 00:00:00 2001
From: Umar Pathan <[email protected]>
Date: Sun, 28 Jun 2026 23:02:52 +0200
Subject: [PATCH] avcodec/rasc: Check that 32-bit DLTA accesses stay within the
 row

Found-by: bikini (github.com/bikini/exploitarium)
Fixes: out of array access
Fixes: rowspill_128x1.avi / gen_rowspill_avi.py
Fixes: xGV79bIb7uAJ
(cherry picked from commit 11ff18a6c80187405fc492f9bb07ba9f2f663f76)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/rasc.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/libavcodec/rasc.c b/libavcodec/rasc.c
index 5f956a9b2c..d784a44063 100644
--- a/libavcodec/rasc.c
+++ b/libavcodec/rasc.c
@@ -320,6 +320,11 @@ static int decode_move(AVCodecContext *avctx,
     return 0;
 }
 
+static inline int dlta_room(unsigned cx, unsigned w, unsigned bpp, unsigned 
need)
+{
+    return cx + need <= w * bpp;
+}
+
 #define NEXT_LINE                        \
     if (cx >= w * s->bpp) {              \
         cx = 0;                          \
@@ -418,6 +423,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 4:
             fill = bytestream2_get_byte(&dc);
             while (len > 0 && cy > 0) {
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx++;
@@ -427,6 +434,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 7:
             fill = bytestream2_get_le32(&dc);
             while (len > 0 && cy > 0) {
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx += 4;
@@ -443,6 +452,8 @@ static int decode_dlta(AVCodecContext *avctx,
             while (len > 0 && cy > 0) {
                 unsigned v0, v1;
 
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 v0 = AV_RL32(b2 + cx);
                 v1 = AV_RL32(b1 + cx);
                 AV_WL32(b2 + cx, v1);
@@ -454,6 +465,8 @@ static int decode_dlta(AVCodecContext *avctx,
         case 13:
             while (len > 0 && cy > 0) {
                 fill = bytestream2_get_le32(&dc);
+                if (!dlta_room(cx, w, s->bpp, 4))
+                    return AVERROR_INVALIDDATA;
                 AV_WL32(b1 + cx, AV_RL32(b2 + cx));
                 AV_WL32(b2 + cx, fill);
                 cx += 4;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-64833.patch ++++++
>From 385ac2fadcb4394ec4f65e5c4d3d24003e090f36 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Tue, 30 Jun 2026 00:11:50 +0200
Subject: [PATCH] avformat/spdifenc: bound DTS core_size against the packet
 size in the HD path

Fixes: out of array read
Fixes: yBSax492UIB9
Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 6f80e2765492700622596af720534cef33dd31b4)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/spdifenc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c
index ab3f73da0d..16eebda01c 100644
--- a/libavformat/spdifenc.c
+++ b/libavformat/spdifenc.c
@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket 
*pkt, int core_size,
              * (dtshd_fallback == 0) */
             ctx->dtshd_skip = 1;
     }
-    if (ctx->dtshd_skip && core_size) {
+    if (ctx->dtshd_skip && core_size && core_size <= pkt->size) {
         pkt_size = core_size;
         if (ctx->dtshd_fallback >= 0)
             --ctx->dtshd_skip;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-64834.patch ++++++
>From 3c441711a343ccf50196c70a3f0b554b52f8d9de Mon Sep 17 00:00:00 2001
From: Pavel Kohout <[email protected]>
Date: Tue, 30 Jun 2026 21:55:16 +0200
Subject: [PATCH] avformat/rtpdec_asf: reject ASF objects smaller than their
 header

Fixes: infinite loop
Fixes: MzWwJdpZF2Ls
Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet 
parsing.)
Found-by: Pavel Kohout (Aisle Research)
Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit 11d5f475be95d22d5f0692220cc772b116abc632)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/rtpdec_asf.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c
index b3b346f3cc..f7fa69e27f 100644
--- a/libavformat/rtpdec_asf.c
+++ b/libavformat/rtpdec_asf.c
@@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len)
         uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid));
         int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2;
         if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) {
+            if (chunksize < sizeof(ff_asf_guid) + 8)
+                return -1;
             if (chunksize > end - p)
                 return -1;
             p += chunksize;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-65703.patch ++++++
>From 3b85fbe89025ea696988488358dfde41a09c53c5 Mon Sep 17 00:00:00 2001
From: Cloud-LHY <[email protected]>
Date: Fri, 10 Jul 2026 04:07:04 +0200
Subject: [PATCH] avcodec/tdsc: unref the reference frame before reallocating
 on size change

Fixes: out of array access
Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
Fixes: tdsc_resize_jpeg_oob.avi / 
tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
Fixes: p9xG4xGf9P7H
Fixes: HQL7a1WgTdHZ
Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS
Found-by: Adrian Junge (vurlo)
(cherry picked from commit fd3ee52fab34d98a95b787d0b5ff45685766200c)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/tdsc.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c
index ca9dd0f0a6..102b4ae966 100644
--- a/libavcodec/tdsc.c
+++ b/libavcodec/tdsc.c
@@ -485,11 +485,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int 
number_tiles)
             return ret;
         init_refframe = 1;
     }
-    ctx->refframe->width  = ctx->width  = w;
-    ctx->refframe->height = ctx->height = h;
+    ctx->width  = w;
+    ctx->height = h;
 
     /* Allocate the reference frame if not already done or on size change */
     if (init_refframe) {
+        av_frame_unref(ctx->refframe);
+        ctx->refframe->format = avctx->pix_fmt;
+        ctx->refframe->width  = w;
+        ctx->refframe->height = h;
         ret = av_frame_get_buffer(ctx->refframe, 0);
         if (ret < 0)
             return ret;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-65704.patch ++++++
>From 52f7983f15678c8a6065327760d7b6eb1c9c84ed Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Fri, 10 Jul 2026 04:07:35 +0200
Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the
 packet size

Fixes: negative-size-param
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)
(cherry picked from commit de771bd52774a52d45b0e2c82e56995a1ef40df7)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavformat/ty.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/ty.c b/libavformat/ty.c
index 9be027fcca..842d97038c 100644
--- a/libavformat/ty.c
+++ b/libavformat/ty.c
@@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr 
*rec_hdr, AVPacket *pkt)
         if (ty->audio_type == TIVO_AUDIO_AC3 &&
                 ty->tivo_series == TIVO_SERIES2) {
             if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) {
-                pkt->size -= 2;
+                pkt->size -= FFMIN(pkt->size, 2);
                 ty->ac3_pkt_size = 0;
             } else {
                 ty->ac3_pkt_size += pkt->size;
-- 
2.49.0


++++++ ffmpeg-4-CVE-2026-65705.patch ++++++
>From 30a52276f9dff60fe732d8bb8d463e587ff69c94 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 03:27:47 +0200
Subject: [PATCH] avfilter/vf_floodfill: remove unneeded variables

Signed-off-by: Michael Niedermayer <[email protected]>
(cherry picked from commit f186c50cf53aec20e9a29059cb22ca3f2d59201c)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_floodfill.c | 35 ++++++++++++++++-------------------
 1 file changed, 16 insertions(+), 19 deletions(-)

diff -a a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
--- a/libavfilter/vf_floodfill.c
+++ b/libavfilter/vf_floodfill.c
@@ -39,7 +39,6 @@ typedef struct FloodfillContext {
     int d[4];
 
     int nb_planes;
-    int back, front;
     Points *points;
 
     int (*is_same)(AVFrame *frame, int x, int y,
@@ -270,7 +269,6 @@ static int config_input(AVFilterLink *in
        }
     }
 
-    s->front = s->back = 0;
     s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points));
     if (!s->points)
         return AVERROR(ENOMEM);
@@ -293,6 +291,7 @@ static int filter_frame(AVFilterLink *li
     const int w = frame->width;
     const int h = frame->height;
     int i, ret;
+    int front = 0;
 
     if (is_inside(s->x, s->y, w, h)) {
         s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
@@ -310,42 +309,42 @@ static int filter_frame(AVFilterLink *li
             goto end;
 
         if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) {
-            s->points[s->front].x = s->x;
-            s->points[s->front].y = s->y;
-            s->front++;
+            s->points[front].x = s->x;
+            s->points[front].y = s->y;
+            front++;
         }
 
         if (ret = av_frame_make_writable(frame))
             return ret;
 
-        while (s->front > s->back) {
+        while (front > 0) {
             int x, y;
 
-            s->front--;
-            x = s->points[s->front].x;
-            y = s->points[s->front].y;
+            front--;
+            x = s->points[front].x;
+            y = s->points[front].y;
 
             if (s->is_same(frame, x, y, s0, s1, s2, s3)) {
                 s->set_pixel(frame, x, y, d0, d1, d2, d3);
 
                 if (is_inside(x + 1, y, w, h)) {
-                    s->points[s->front]  .x = x + 1;
-                    s->points[s->front++].y = y;
+                    s->points[front]  .x = x + 1;
+                    s->points[front++].y = y;
                 }
 
                 if (is_inside(x - 1, y, w, h)) {
-                    s->points[s->front]  .x = x - 1;
-                    s->points[s->front++].y = y;
+                    s->points[front]  .x = x - 1;
+                    s->points[front++].y = y;
                 }
 
                 if (is_inside(x, y + 1, w, h)) {
-                    s->points[s->front]  .x = x;
-                    s->points[s->front++].y = y + 1;
+                    s->points[front]  .x = x;
+                    s->points[front++].y = y + 1;
                 }
 
                 if (is_inside(x, y - 1, w, h)) {
-                    s->points[s->front]  .x = x;
-                    s->points[s->front++].y = y - 1;
+                    s->points[front]  .x = x;
+                    s->points[front++].y = y - 1;
                 }
             }
         }

++++++ ffmpeg-4-CVE-2026-65706.patch ++++++
>From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sat, 11 Jul 2026 16:46:39 +0200
Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest
 plane

Fixes: out of array access
Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
Fixes: VRAXYvKtmKa8
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_swaprect.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c
index 5d93f51c30..fe007ee5e7 100644
--- a/libavfilter/vf_swaprect.c
+++ b/libavfilter/vf_swaprect.c
@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink)
 {
     AVFilterContext *ctx = inlink->dst;
     SwapRectContext *s = ctx->priv;
+    int size = 0;

     if (!s->w  || !s->h  ||
         !s->x1 || !s->y1 ||
@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink)
     av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc);
     s->nb_planes = av_pix_fmt_count_planes(inlink->format);

-    s->temp = av_malloc_array(inlink->w, s->pixsteps[0]);
+    for (int p = 0; p < s->nb_planes; p++) {
+        int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0;
+        int width = AV_CEIL_RSHIFT(inlink->w, shift);
+
+        if (width > INT_MAX / s->pixsteps[p])
+            return AVERROR(EINVAL);
+        size = FFMAX(size, width * s->pixsteps[p]);
+    }
+
+    s->temp = av_malloc(size);
     if (!s->temp)
         return AVERROR(ENOMEM);

-- 
2.49.0

++++++ ffmpeg-4-CVE-2026-66036-shim01.patch ++++++
>From e3d0c719fddd259709c8e275942ab56af3afc35d Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sun, 12 Jul 2026 13:05:07 +0200
Subject: [PATCH] avfilter/vf_hqdn3d: reject unsupported frame parameter
 changes

Fixes: out of array access
Fixes: 9aj_hqdn3d_dynamic_res.mjpg / 9aj_generate_hqdn3d_dynamic_res_mjpg.py
Fixes: wWDsy2oDvMuR
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit f0f634b6585fdc7bbb43ab3ae461499bfca9ad2e)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_hqdn3d.c | 34 +++++++++++++++++++++++++---------
 libavfilter/vf_hqdn3d.h |  2 ++
 2 files changed, 27 insertions(+), 9 deletions(-)

diff -a a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c
--- a/libavfilter/vf_hqdn3d.c
+++ b/libavfilter/vf_hqdn3d.c
@@ -164,12 +164,8 @@ static int denoise_depth(HQDN3DContext *
             case 14: ret = denoise_depth(__VA_ARGS__, 14); break;             \
             case 16: ret = denoise_depth(__VA_ARGS__, 16); break;             \
         }                                                                     \
-        if (ret < 0) {                                                        \
-            av_frame_free(&out);                                              \
-            if (!direct)                                                      \
-                av_frame_free(&in);                                           \
+        if (ret < 0)                                                          \
             return ret;                                                       \
-        }                                                                     \
     } while (0)
 
 static void precalc_coefs(double dist25, int depth, int16_t *ct)
@@ -288,12 +284,15 @@ static int config_input(AVFilterLink *in
     if (ARCH_X86)
         ff_hqdn3d_init_x86(s);
 
+    s->format = inlink->format;
+    s->width  = inlink->w;
+    s->height = inlink->h;
+
     return 0;
 }
 
 typedef struct ThreadData {
     AVFrame *in, *out;
-    int direct;
 } ThreadData;
 
 static int do_denoise(AVFilterContext *ctx, void *data, int job_nr, int n_jobs)
@@ -302,7 +301,6 @@ static int do_denoise(AVFilterContext *c
     const ThreadData *td = data;
     AVFrame *out = td->out;
     AVFrame *in = td->in;
-    int direct = td->direct;
 
     denoise(s, in->data[job_nr], out->data[job_nr],
                 s->line[job_nr], &s->frame_prev[job_nr],
@@ -319,10 +317,21 @@ static int filter_frame(AVFilterLink *in
 {
     AVFilterContext *ctx  = inlink->dst;
     AVFilterLink *outlink = ctx->outputs[0];
+    HQDN3DContext *s = ctx->priv;
 
     AVFrame *out;
     int direct = av_frame_is_writable(in) && !ctx->is_disabled;
     ThreadData td;
+    int ret[3];
+
+    if (in->format != s->format ||
+        in->width  != s->width  ||
+        in->height != s->height) {
+        av_log(ctx, AV_LOG_ERROR,
+               "Frame size or format changed without filter graph 
reinitialization\n");
+        av_frame_free(&in);
+        return AVERROR(EINVAL);
+    }
 
     if (direct) {
         out = in;
@@ -338,9 +347,16 @@ static int filter_frame(AVFilterLink *in
 
     td.in = in;
     td.out = out;
-    td.direct = direct;
     /* one thread per plane */
-    ctx->internal->execute(ctx, do_denoise, &td, NULL, 3);
+    ctx->internal->execute(ctx, do_denoise, &td, ret, 3);
+    for (int i = 0; i < FF_ARRAY_ELEMS(ret); i++) {
+        if (ret[i] < 0) {
+            av_frame_free(&out);
+            if (!direct)
+                av_frame_free(&in);
+            return ret[i];
+        }
+    }
 
     if (ctx->is_disabled) {
         av_frame_free(&out);

diff -a a/libavfilter/vf_hqdn3d.h b/libavfilter/vf_hqdn3d.h
--- a/libavfilter/vf_hqdn3d.h
+++ b/libavfilter/vf_hqdn3d.h
@@ -36,6 +36,8 @@ typedef struct HQDN3DContext {
     double strength[4];
     int hsub, vsub;
     int depth;
+    int width, height;
+    enum AVPixelFormat format;
     void (*denoise_row[17])(uint8_t *src, uint8_t *dst, uint16_t *line_ant, 
uint16_t *frame_ant, ptrdiff_t w, int16_t *spatial, int16_t *temporal);
 } HQDN3DContext;
 

++++++ ffmpeg-4-CVE-2026-66036.patch ++++++
>From b3c7ebc1edc401fd9881277fdfae93f3f24ceb81 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Sat, 11 Jul 2026 16:46:39 +0200
Subject: [PATCH] avfilter/vf_swaprect: size the temp row buffer for the widest
 plane

Fixes: out of array access
Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
Fixes: VRAXYvKtmKa8
Found-by: Adrian Junge (vurlo) <[email protected]>
(cherry picked from commit a7e38b617b32f996beaa371bbf04b39907d7a527)
Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavfilter/vf_swaprect.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff a/libavfilter/avfilter.c b/libavfilter/avfilter.c
--- a/libavfilter/avfilter.c
+++ b/libavfilter/avfilter.c
@@ -1104,7 +1104,8 @@ int ff_filter_frame(AVFilterLink *link,
             strcmp(link->dst->filter->name, "format") &&
             strcmp(link->dst->filter->name, "idet") &&
             strcmp(link->dst->filter->name, "null") &&
-            strcmp(link->dst->filter->name, "scale")) {
+            strcmp(link->dst->filter->name, "scale") &&
+            strcmp(link->dst->filter->name, "hqdn3d")) {
             av_assert1(frame->format                 == link->format);
             av_assert1(frame->width               == link->w);
             av_assert1(frame->height               == link->h);

diff a/libavfilter/vf_hqdn3d.c b/libavfilter/vf_hqdn3d.c
--- a/libavfilter/vf_hqdn3d.c
+++ b/libavfilter/vf_hqdn3d.c
@@ -322,21 +322,28 @@ static int filter_frame(AVFilterLink *in
     AVFrame *out;
     int direct = av_frame_is_writable(in) && !ctx->is_disabled;
     ThreadData td;
-    int ret[3];
+    int err, ret[3];

-    if (in->format != s->format ||
-        in->width  != s->width  ||
-        in->height != s->height) {
-        av_log(ctx, AV_LOG_ERROR,
-               "Frame size or format changed without filter graph 
reinitialization\n");
+    if (in->format != s->format) {
         av_frame_free(&in);
         return AVERROR(EINVAL);
     }

+    if (in->width != s->width || in->height != s->height) {
+        inlink->w = in->width;
+        inlink->h = in->height;
+        if ((err = config_input(inlink)) < 0) {
+            av_frame_free(&in);
+            return err;
+        }
+        outlink->w = in->width;
+        outlink->h = in->height;
+    }
+
     if (direct) {
         out = in;
     } else {
-        out = ff_get_video_buffer(outlink, outlink->w, outlink->h);
+        out = ff_get_video_buffer(outlink, in->width, in->height);
         if (!out) {
             av_frame_free(&in);
             return AVERROR(ENOMEM);

Reply via email to