Commit edc96a209b for ffmpeg
commit edc96a209b25b78d3e4b96e951774eb13c8da0b0
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 06:52:22 2026 +0200
avformat/libmodplug: Allocate the buffer for the bytes that are read
The allocation size is the one recommended in the report.
Fixes: out of array write
Fixes: QDheAEkG6X39
Fixes: AISLE-2026-0111-00036
Out of array write Replicated through UnModified FFmpeg with ASAN
Found-by: Joshua Rogers <joshua.rogers@aisle.com>
diff --git a/libavformat/libmodplug.c b/libavformat/libmodplug.c
index 01566d121e..d9ab14b3bc 100644
--- a/libavformat/libmodplug.c
+++ b/libavformat/libmodplug.c
@@ -197,7 +197,7 @@ static int modplug_read_header(AVFormatContext *s)
return r;
}
- modplug->buf = av_malloc(modplug->max_size);
+ modplug->buf = av_malloc(sz);
if (!modplug->buf)
return AVERROR(ENOMEM);
sz = avio_read(pb, modplug->buf, sz);