Commit 0e8c740378 for ffmpeg
commit 0e8c7403780e3276c149ea79b9c1e03bedb21a25
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Thu Sep 24 00:44:25 2026 +0200
avcodec/hevc: reject a slice whose layer is not in the VPS of its SPS
Fixes: out of array read
Fixes: undefined shift
Fixes: 3JrnwpkctVpF
Fixes: hevc_layer_idx_oob.hevc
Fixes: poc.hevc
Replicated through UnModified FFmpeg
Replicated through API
Regression since: 02a9435cb0
Found-by: Glops Elemiu
Found-by: Kasif Dekel
diff --git a/libavcodec/hevc/hevcdec.c b/libavcodec/hevc/hevcdec.c
index b6234a6c34..9bbe6fe5a5 100644
--- a/libavcodec/hevc/hevcdec.c
+++ b/libavcodec/hevc/hevcdec.c
@@ -793,8 +793,8 @@ static int hls_slice_header(SliceHeader *sh, const HEVCContext *s, GetBitContext
const HEVCPPS *pps;
const HEVCSPS *sps;
const HEVCVPS *vps;
- unsigned pps_id, layer_idx;
- int i, ret;
+ unsigned pps_id;
+ int i, ret, layer_idx;
// Coded parameters
sh->first_slice_in_pic_flag = get_bits1(gb);
@@ -818,6 +818,10 @@ static int hls_slice_header(SliceHeader *sh, const HEVCContext *s, GetBitContext
sps = pps->sps;
vps = sps->vps;
layer_idx = vps->layer_idx[s->nuh_layer_id];
+ if (layer_idx < 0) {
+ av_log(s->avctx, AV_LOG_ERROR, "Layer %d is not in the VPS\n", s->nuh_layer_id);
+ return AVERROR_INVALIDDATA;
+ }
if (s->nal_unit_type == HEVC_NAL_CRA_NUT && s->last_eos == 1)
sh->no_output_of_prior_pics_flag = 1;