This is an automated email from the git hooks/post-receive script.

Git pushed a commit to branch master
in repository ffmpeg.

The following commit(s) were added to refs/heads/master by this push:
     new 6d6f5fbf13 avcodec/snowenc: check the frame number against the pass-2 
statistics before indexing them
6d6f5fbf13 is described below

commit 6d6f5fbf13e2897c5181b2d251646cf371bf342c
Author:     Hongduo Zhao <[email protected]>
AuthorDate: Fri Sep 25 05:34:29 2026 +0200
Commit:     michaelni <[email protected]>
CommitDate: Sun Oct 4 20:57:15 2026 +0000

    avcodec/snowenc: check the frame number against the pass-2 statistics 
before indexing them
    
    Fixes: heap-buffer-overflow
    Fixes: d8mJHYOGopsd
    Found-by: Hongduo Zhao
---
 libavcodec/snowenc.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/libavcodec/snowenc.c b/libavcodec/snowenc.c
index 45446e5479..13ca651fcd 100644
--- a/libavcodec/snowenc.c
+++ b/libavcodec/snowenc.c
@@ -1807,6 +1807,11 @@ static int encode_frame(AVCodecContext *avctx, AVPacket 
*pkt,
 
     mpv->picture_number = avctx->frame_num;
     if(avctx->flags&AV_CODEC_FLAG_PASS2){
+        if (avctx->frame_num >= enc->m.rc_context.num_entries) {
+            av_log(avctx, AV_LOG_ERROR,
+                   "Pass-2 statistics contain fewer frames than the input.\n");
+            return AVERROR_INVALIDDATA;
+        }
         mpv->c.pict_type = pic->pict_type = 
enc->m.rc_context.entry[avctx->frame_num].new_pict_type;
         s->keyframe = pic->pict_type == AV_PICTURE_TYPE_I;
         if(!(avctx->flags&AV_CODEC_FLAG_QSCALE)) {

-- 
To stop receiving notification emails like this one, please contact
[email protected].
_______________________________________________
ffmpeg-cvslog mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to