Commit 301a611370 for ffmpeg
commit 301a611370a0ba81f4a71d3b7ccd064623606c1b
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 07:10:44 2026 +0200
avformat/imf_cpl: Do not free the marker label on scope allocation failure
Fixes: double free
Fixes: JLKmGHU1qVX5
Fixes: AISLE-2026-0111-00365
Double free Replicated through API with ASAN and an injected libxml2 allocation failure
Found-by: Joshua Rogers <joshua.rogers@aisle.com>
diff --git a/libavformat/imf_cpl.c b/libavformat/imf_cpl.c
index 8c3530f412..dba502007c 100644
--- a/libavformat/imf_cpl.c
+++ b/libavformat/imf_cpl.c
@@ -311,10 +311,8 @@ static int fill_marker(xmlNodePtr marker_elem, FFIMFMarker *marker)
if (!(marker->scope_utf8 = xmlGetNoNsProp(element, "scope"))) {
marker->scope_utf8
= xmlCharStrdup("http://www.smpte-ra.org/schemas/2067-3/2013#standard-markers");
- if (!marker->scope_utf8) {
- xmlFree(marker->label_utf8);
+ if (!marker->scope_utf8)
return AVERROR(ENOMEM);
- }
}
return ret;