PR #24592 opened by michaelni URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592.patch
Fixes: Timeout Fixes: q8954W25MJoa Fixes: AISLE-2026-0100-00001 Found-by: Joshua Rogers <[email protected]> Signed-off-by: Michael Niedermayer <[email protected]> >From 59596b08f9c8118c7f275023a631895a7edcd79c Mon Sep 17 00:00:00 2001 From: Joshua Rogers <[email protected]> Date: Mon, 31 Aug 2026 15:31:50 +0200 Subject: [PATCH 1/2] avutil/avstring: fix infinite loop in av_strireplace with empty search string av_stristr() returns the input pointer unchanged for an empty needle, so an empty 'from' argument left pstr never advancing and caused av_strireplace() to loop forever (and grow the buffer unboundedly if 'to' was non-empty). Return a duplicate of 'str' when 'from' is empty. Fixes: Timeout Fixes: q8954W25MJoa Fixes: AISLE-2026-0100-00001 Found-by: Joshua Rogers <[email protected]> Signed-off-by: Michael Niedermayer <[email protected]> --- libavutil/avstring.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/libavutil/avstring.c b/libavutil/avstring.c index 1487297cba..9b81da33bf 100644 --- a/libavutil/avstring.c +++ b/libavutil/avstring.c @@ -234,6 +234,9 @@ char *av_strireplace(const char *str, const char *from, const char *to) size_t tolen = strlen(to), fromlen = strlen(from); AVBPrint pbuf; + if (!fromlen) + return av_strdup(str); + av_bprint_init(&pbuf, 1, AV_BPRINT_SIZE_UNLIMITED); while ((pstr2 = av_stristr(pstr, from))) { av_bprint_append_data(&pbuf, pstr, pstr2 - pstr); -- 2.52.0 >From 5fab0973c272cf422204669ffe7fe051d1b627fd Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 20 Sep 2026 00:04:04 +0200 Subject: [PATCH 2/2] avformat/dashdec: return EOF when a byte-range segment is exhausted Fixes: Timeout Fixes: t593bxSA0XOy Found during triage/review of the security report q8954W25MJoa Signed-off-by: Michael Niedermayer <[email protected]> --- libavformat/dashdec.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/libavformat/dashdec.c b/libavformat/dashdec.c index 740ac6bc1c..7230b6a6d6 100644 --- a/libavformat/dashdec.c +++ b/libavformat/dashdec.c @@ -1747,8 +1747,11 @@ static int read_from_url(struct representation *pls, struct fragment *seg, int ret; /* limit read if the fragment was only a part of a file */ - if (seg->size >= 0) + if (seg->size >= 0) { buf_size = FFMIN(buf_size, pls->cur_seg_size - pls->cur_seg_offset); + if (buf_size <= 0) + return AVERROR_EOF; + } ret = avio_read(pls->input, buf, buf_size); if (ret > 0) -- 2.52.0 _______________________________________________ ffmpeg-devel mailing list -- [email protected] To unsubscribe send an email to [email protected]
