PR #22978 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22978
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22978.patch
Reject INFO list chunks that are too small to contain the expected
4-byte list type field before calling ff_read_riff_info().
The parser subtracts 4 from the list size when handing the remaining
payload to ff_read_riff_info(). If the chunk is smaller than 4 bytes,
that underflows the expected structure and should be treated as invalid
input.
Fixes: DFVULN-607
*Vulnerability reported by Zhenpeng (Leo) Lin at depthfirst*
*Patch validated by Zheng Yu at depthfirst*
>From 4e183d2d1c0a79100384c5ceb443ad9ab66b760f Mon Sep 17 00:00:00 2001
From: "depthfirst-dev[bot]"
<1012587+depthfirst-dev[bot]@users.noreply.github.com>
Date: Thu, 23 Apr 2026 02:47:11 +0000
Subject: [PATCH] avformat/avidec: validate INFO list size before parsing
Reject INFO list chunks that are too small to contain the expected
4-byte list type field before calling ff_read_riff_info().
The parser subtracts 4 from the list size when handing the remaining
payload to ff_read_riff_info(). If the chunk is smaller than 4 bytes,
that underflows the expected structure and should be treated as invalid
input.
Fixes: DFVULN-607
*Vulnerability reported by Zhenpeng (Leo) Lin at depthfirst*
*Patch validated by Zheng Yu at depthfirst*
---
libavformat/avidec.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/libavformat/avidec.c b/libavformat/avidec.c
index eb9bfb15ea..db01244853 100644
--- a/libavformat/avidec.c
+++ b/libavformat/avidec.c
@@ -562,9 +562,11 @@ static int avi_read_header(AVFormatContext *s)
avi->movi_end = avi->fsize;
av_log(s, AV_LOG_TRACE, "movi end=%"PRIx64"\n", avi->movi_end);
goto end_of_header;
- } else if (tag1 == MKTAG('I', 'N', 'F', 'O'))
+ } else if (tag1 == MKTAG('I', 'N', 'F', 'O')) {
+ if (size < 4)
+ return AVERROR_INVALIDDATA;
ff_read_riff_info(s, size - 4);
- else if (tag1 == MKTAG('n', 'c', 'd', 't'))
+ } else if (tag1 == MKTAG('n', 'c', 'd', 't'))
avi_read_nikon(s, list_end);
break;
--
2.52.0
_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]