Commit e61908e508 for ffmpeg
commit e61908e508c2aa99b726b5529192ac0a04c8a437
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Wed Oct 7 03:08:56 2026 +0200
avformat/rtpenc_vc2hq: Read the quantization matrix as specified
Not a security issue.
Fixes: lJyVgdTNfBGb
Wrong transform parameters length Replicated through UnModified FFmpeg
Found during triage of the security report nd3rLqSpKgo5
diff --git a/libavformat/rtpenc_vc2hq.c b/libavformat/rtpenc_vc2hq.c
index 7a422910bb..fdb0b9ad0c 100644
--- a/libavformat/rtpenc_vc2hq.c
+++ b/libavformat/rtpenc_vc2hq.c
@@ -77,14 +77,16 @@ static int send_picture(AVFormatContext *ctx, const uint8_t *buf, int size, int
prefix_bytes = get_interleaved_ue_golomb(&gc);
size_scaler = get_interleaved_ue_golomb(&gc);
/* pass the quantization matrices */
- get_interleaved_ue_golomb(&gc);
- for(lvl = 0; lvl < wavelet_depth; lvl++)
- {
- if (get_bits_left(&gc) < 0)
- return AVERROR_INVALIDDATA;
- get_interleaved_ue_golomb(&gc);
- get_interleaved_ue_golomb(&gc);
+ if (get_bits1(&gc)) {
get_interleaved_ue_golomb(&gc);
+ for(lvl = 0; lvl < wavelet_depth; lvl++)
+ {
+ if (get_bits_left(&gc) < 0)
+ return AVERROR_INVALIDDATA;
+ get_interleaved_ue_golomb(&gc);
+ get_interleaved_ue_golomb(&gc);
+ get_interleaved_ue_golomb(&gc);
+ }
}
frag_len = (get_bits_count(&gc) + 7) / 8; /* length of transform parameters */