Commit 73822ed864 for ffmpeg
commit 73822ed864d3c5975480bdf5fda3f7810a2a5c1a
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Fri Oct 2 19:53:39 2026 +0200
avformat/rtpenc_rfc4175: Start the second field at frame line 1
The line counter of the second field started at 0 like the one of the
first field. With an odd height the second field thus ended with a line
below the last line of the frame, which was sent with stale data from
the packet buffer.
Fixes: line below the frame sent with stale data
Found during triage of the security report fKcw8qCE1cYW
Replicated through UnModified FFmpeg
diff --git a/libavformat/rtpenc_rfc4175.c b/libavformat/rtpenc_rfc4175.c
index e7c8b2c02b..2bfbfaa88e 100644
--- a/libavformat/rtpenc_rfc4175.c
+++ b/libavformat/rtpenc_rfc4175.c
@@ -27,7 +27,7 @@ void ff_rtp_send_raw_rfc4175(AVFormatContext *s1, const uint8_t *buf, int size,
int width = s1->streams[0]->codecpar->width;
int height = s1->streams[0]->codecpar->height;
int xinc, yinc, pgroup;
- int i = 0;
+ int i = field;
int offset = 0;
s->timestamp = s->cur_timestamp;