Commit b0a76ded81 for ffmpeg
commit b0a76ded815f1911b4a3f9467c73811fc666dc40
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Wed Sep 23 23:52:30 2026 +0200
avformat/vivo: fail on a short read of a text header packet
Not really a security issue
Fixes: stale header text parsed after a short read
Fixes: gvif3SQQV4tm
Found-by: zhang xingxing
Suggested-by: zhang xingxing
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
diff --git a/libavformat/vivo.c b/libavformat/vivo.c
index c20788f8bb..20e51d0082 100644
--- a/libavformat/vivo.c
+++ b/libavformat/vivo.c
@@ -29,6 +29,7 @@
#include "libavutil/avstring.h"
#include "libavutil/parseutils.h"
#include "avformat.h"
+#include "avio_internal.h"
#include "demux.h"
#include "internal.h"
@@ -146,7 +147,8 @@ static int vivo_read_header(AVFormatContext *s)
break;
if (vivo->length <= 1024) {
- avio_read(s->pb, vivo->text, vivo->length);
+ if ((ret = ffio_read_size(s->pb, vivo->text, vivo->length)) < 0)
+ return ret;
vivo->text[vivo->length] = 0;
} else {
av_log(s, AV_LOG_WARNING, "too big header, skipping\n");