Commit 466ea98db4 for ffmpeg
commit 466ea98db4a040491d0fc248d55f8c44a86477e2
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Sun Oct 4 23:43:40 2026 +0200
avformat/mov: do not seek back to cache ipco properties
This could use ffio_ensure_seekback() but simply storing the 2 values
is simpler
no memory safety issue is known to depend on it.
Found-by: OpenAI Security Research
Reported in the security report srZp1wXh4CXQ
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
diff --git a/libavformat/mov.c b/libavformat/mov.c
index 2eb79c702b..fb1b91772b 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -9940,8 +9940,9 @@ static int mov_read_iprp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
goto fail;
}
av_log(c->fc, AV_LOG_TRACE, "ipco: index %d, box type %s\n", nb_atoms, av_fourcc2str(ref->type));
- avio_seek(pb, -8, SEEK_CUR);
- if (avio_read(pb, ref->data, ref->size) != ref->size) {
+ AV_WB32(ref->data, ref->size);
+ AV_WL32(ref->data + 4, ref->type);
+ if (avio_read(pb, ref->data + 8, ref->size - 8) != ref->size - 8) {
ret = AVERROR_INVALIDDATA;
goto fail;
}