This is an automated email from the git hooks/post-receive script. Git pushed a commit to branch master in repository ffmpeg.
commit 3322ac16469fc82695bbc2e3e286f01acf8addbc Author: Niklas Haas <[email protected]> AuthorDate: Sat Sep 5 13:51:57 2026 +0200 Commit: Niklas Haas <[email protected]> CommitDate: Tue Sep 29 20:16:33 2026 +0200 avformat/libcurl: guard against overflow from undelimited responses verify_content_range() already clamps down on the valid byte range for 206 replies (or 200 replies with a Content-Length), but an undelimited response represents an escape path that can still trigger overflow here. Signed-off-by: Niklas Haas <[email protected]> --- libavformat/libcurl.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/libavformat/libcurl.c b/libavformat/libcurl.c index d8dc44d652..57e413df05 100644 --- a/libavformat/libcurl.c +++ b/libavformat/libcurl.c @@ -240,6 +240,19 @@ static size_t write_callback(char *ptr, size_t size, size_t nmemb, void *userdat return bytes; /* discard */ } + /* Prevent overflow / non-addressable byte ranges */ + if (bytes > INT64_MAX - c->request_start - c->request_received) { + av_log(c->h, AV_LOG_ERROR, "Server sent back more data than addressable " + "at offset %"PRId64"\n", c->request_start); + c->loop->num_errors++; + c->stream_ok = 0; + if (!c->status) + c->status = AVERROR(ERANGE); + pthread_cond_broadcast(&c->cond); + pthread_mutex_unlock(&c->mutex); + return CURL_WRITEFUNC_ERROR; + } + space = av_fifo_can_write(c->fifo); if (space < bytes) { /* pause the transfer and wait for the consumer to drain. */ -- To stop receiving notification emails like this one, please contact [email protected]. _______________________________________________ ffmpeg-cvslog mailing list -- [email protected] To unsubscribe send an email to [email protected]
