Commit 3322ac1646 for ffmpeg

commit 3322ac16469fc82695bbc2e3e286f01acf8addbc
Author: Niklas Haas <git@haasn.dev>
Date:   Sat Sep 5 13:51:57 2026 +0200

    avformat/libcurl: guard against overflow from undelimited responses

    verify_content_range() already clamps down on the valid byte range for
    206 replies (or 200 replies with a Content-Length), but an undelimited
    response represents an escape path that can still trigger overflow here.

    Signed-off-by: Niklas Haas <git@haasn.dev>

diff --git a/libavformat/libcurl.c b/libavformat/libcurl.c
index d8dc44d652..57e413df05 100644
--- a/libavformat/libcurl.c
+++ b/libavformat/libcurl.c
@@ -240,6 +240,19 @@ static size_t write_callback(char *ptr, size_t size, size_t nmemb, void *userdat
         return bytes; /* discard */
     }

+    /* Prevent overflow / non-addressable byte ranges */
+    if (bytes > INT64_MAX - c->request_start - c->request_received) {
+        av_log(c->h, AV_LOG_ERROR, "Server sent back more data than addressable "
+               "at offset %"PRId64"\n", c->request_start);
+        c->loop->num_errors++;
+        c->stream_ok = 0;
+        if (!c->status)
+            c->status = AVERROR(ERANGE);
+        pthread_cond_broadcast(&c->cond);
+        pthread_mutex_unlock(&c->mutex);
+        return CURL_WRITEFUNC_ERROR;
+    }
+
     space = av_fifo_can_write(c->fifo);
     if (space < bytes) {
         /* pause the transfer and wait for the consumer to drain. */