forked from jengelh/ffmpeg-4
Compare commits
6 Commits
Author | SHA256 | Date | |
---|---|---|---|
c97634de0a | |||
7a9fc524c2 | |||
b0492f2178 | |||
420e661938 | |||
86b52e2cf6 | |||
2ddfcb257c |
@@ -1,58 +0,0 @@
|
|||||||
From 654bd47716c4f36719fb0f3f7fd8386d5ed0b916 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Ross Burton <ross.burton@arm.com>
|
|
||||||
Date: Fri, 9 Aug 2024 11:32:00 +0100
|
|
||||||
Subject: [PATCH] libavcodec/arm/mlpdsp_armv5te: fix label format to work with
|
|
||||||
binutils 2.43
|
|
||||||
MIME-Version: 1.0
|
|
||||||
Content-Type: text/plain; charset=UTF-8
|
|
||||||
Content-Transfer-Encoding: 8bit
|
|
||||||
|
|
||||||
binutils 2.43 has stricter validation for labels[1] and results in errors
|
|
||||||
when building ffmpeg for armv5:
|
|
||||||
|
|
||||||
src/libavcodec/arm/mlpdsp_armv5te.S:232: Error: junk at end of line, first unrecognized character is `0'
|
|
||||||
|
|
||||||
Remove the leading zero in the "01" label to resolve this error.
|
|
||||||
|
|
||||||
[1] https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=226749d5a6ff0d5c607d6428d6c81e1e7e7a994b
|
|
||||||
|
|
||||||
Signed-off-by: Ross Burton <ross.burton@arm.com>
|
|
||||||
Signed-off-by: Martin Storsjö <martin@martin.st>
|
|
||||||
---
|
|
||||||
libavcodec/arm/mlpdsp_armv5te.S | 6 +++---
|
|
||||||
1 file changed, 3 insertions(+), 3 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/libavcodec/arm/mlpdsp_armv5te.S b/libavcodec/arm/mlpdsp_armv5te.S
|
|
||||||
index 4f9aa485fd..d31568611c 100644
|
|
||||||
--- a/libavcodec/arm/mlpdsp_armv5te.S
|
|
||||||
+++ b/libavcodec/arm/mlpdsp_armv5te.S
|
|
||||||
@@ -229,7 +229,7 @@ A .endif
|
|
||||||
.endif
|
|
||||||
|
|
||||||
// Begin loop
|
|
||||||
-01:
|
|
||||||
+1:
|
|
||||||
.if TOTAL_TAPS == 0
|
|
||||||
// Things simplify a lot in this case
|
|
||||||
// In fact this could be pipelined further if it's worth it...
|
|
||||||
@@ -241,7 +241,7 @@ A .endif
|
|
||||||
str ST0, [PST, #-4]!
|
|
||||||
str ST0, [PST, #4 * (MAX_BLOCKSIZE + MAX_FIR_ORDER)]
|
|
||||||
str ST0, [PSAMP], #4 * MAX_CHANNELS
|
|
||||||
- bne 01b
|
|
||||||
+ bne 1b
|
|
||||||
.else
|
|
||||||
.if \fir_taps & 1
|
|
||||||
.set LOAD_REG, 1
|
|
||||||
@@ -333,7 +333,7 @@ T orr AC0, AC0, AC1
|
|
||||||
str ST3, [PST, #-4]!
|
|
||||||
str ST2, [PST, #4 * (MAX_BLOCKSIZE + MAX_FIR_ORDER)]
|
|
||||||
str ST3, [PSAMP], #4 * MAX_CHANNELS
|
|
||||||
- bne 01b
|
|
||||||
+ bne 1b
|
|
||||||
.endif
|
|
||||||
b 99f
|
|
||||||
|
|
||||||
--
|
|
||||||
2.46.0
|
|
||||||
|
|
23
ffmpeg-4-CVE-2024-36618.patch
Normal file
23
ffmpeg-4-CVE-2024-36618.patch
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
commit 7a089ed8e049e3bfcb22de1250b86f2106060857
|
||||||
|
Author: Andreas Rheinhardt <andreas.rheinhardt@outlook.com>
|
||||||
|
Date: Tue Mar 12 23:23:17 2024 +0100
|
||||||
|
|
||||||
|
avformat/avidec: Fix integer overflow iff ULONG_MAX < INT64_MAX
|
||||||
|
|
||||||
|
Affects many FATE-tests, see
|
||||||
|
https://fate.ffmpeg.org/report.cgi?time=20240312011016&slot=ppc-linux-gcc-13.2-ubsan-altivec-qemu
|
||||||
|
|
||||||
|
Reviewed-by: James Almer <jamrial@gmail.com>
|
||||||
|
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@outlook.com>
|
||||||
|
|
||||||
|
--- a/libavformat/avidec.c
|
||||||
|
+++ b/libavformat/avidec.c
|
||||||
|
@@ -1694,7 +1694,7 @@
|
||||||
|
int *idx = av_mallocz_array(s->nb_streams, sizeof(*idx));
|
||||||
|
if (!idx)
|
||||||
|
return AVERROR(ENOMEM);
|
||||||
|
- for (min_pos = pos = 0; min_pos != INT64_MAX; pos = min_pos + 1LU) {
|
||||||
|
+ for (min_pos = pos = 0; min_pos != INT64_MAX; pos = min_pos + 1ULL) {
|
||||||
|
int64_t max_dts = INT64_MIN / 2;
|
||||||
|
int64_t min_dts = INT64_MAX / 2;
|
||||||
|
int64_t max_buffer = 0;
|
@@ -1,29 +0,0 @@
|
|||||||
From b5b6391d64807578ab872dc58fb8aa621dcfc38a Mon Sep 17 00:00:00 2001
|
|
||||||
From: Michael Niedermayer <michael@niedermayer.cc>
|
|
||||||
Date: Mon, 6 Jan 2025 22:01:39 +0100
|
|
||||||
Subject: [PATCH] avfilter/af_pan: Fix sscanf() use
|
|
||||||
|
|
||||||
Fixes: Memory Data Leak
|
|
||||||
|
|
||||||
Found-by: Simcha Kosman <simcha.kosman@cyberark.com>
|
|
||||||
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
|
|
||||||
---
|
|
||||||
libavfilter/af_pan.c | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/libavfilter/af_pan.c b/libavfilter/af_pan.c
|
|
||||||
index 0d20b0307b..5feb2439c7 100644
|
|
||||||
--- a/libavfilter/af_pan.c
|
|
||||||
+++ b/libavfilter/af_pan.c
|
|
||||||
@@ -196,7 +196,7 @@ static av_cold int init(AVFilterContext *ctx)
|
|
||||||
sign = 1;
|
|
||||||
while (1) {
|
|
||||||
gain = 1;
|
|
||||||
- if (sscanf(arg, "%lf%n *%n", &gain, &len, &len))
|
|
||||||
+ if (sscanf(arg, "%lf%n *%n", &gain, &len, &len) >= 1)
|
|
||||||
arg += len;
|
|
||||||
if (parse_channel_name(&arg, &in_ch_id, &named)){
|
|
||||||
av_log(ctx, AV_LOG_ERROR,
|
|
||||||
--
|
|
||||||
2.44.0
|
|
||||||
|
|
@@ -1,29 +0,0 @@
|
|||||||
From 1446e37d3d032e1452844778b3e6ba2c20f0c322 Mon Sep 17 00:00:00 2001
|
|
||||||
From: James Almer <jamrial@gmail.com>
|
|
||||||
Date: Mon, 30 Dec 2024 00:25:41 -0300
|
|
||||||
Subject: [PATCH] avfilter/buffersrc: check for valid sample rate
|
|
||||||
|
|
||||||
A sample rate <= 0 is invalid.
|
|
||||||
|
|
||||||
Fixes an assert in ffmpeg_enc.c that assumed a valid sample rate would be set.
|
|
||||||
Fixes ticket #11385.
|
|
||||||
|
|
||||||
Signed-off-by: James Almer <jamrial@gmail.com>
|
|
||||||
---
|
|
||||||
libavfilter/buffersrc.c | 5 +++++
|
|
||||||
1 file changed, 5 insertions(+)
|
|
||||||
|
|
||||||
--- a/libavfilter/buffersrc.c
|
|
||||||
+++ b/libavfilter/buffersrc.c
|
|
||||||
@@ -337,6 +337,11 @@
|
|
||||||
return AVERROR(EINVAL);
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (s->sample_rate <= 0) {
|
|
||||||
+ av_log(ctx, AV_LOG_ERROR, "Sample rate not set\n");
|
|
||||||
+ return AVERROR(EINVAL);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
if (!s->time_base.num)
|
|
||||||
s->time_base = (AVRational){1, s->sample_rate};
|
|
||||||
|
|
BIN
ffmpeg-4.4.5.tar.xz
(Stored with Git LFS)
BIN
ffmpeg-4.4.5.tar.xz
(Stored with Git LFS)
Binary file not shown.
@@ -1,11 +0,0 @@
|
|||||||
-----BEGIN PGP SIGNATURE-----
|
|
||||||
|
|
||||||
iQFMBAABCgA2FiEE/PmG6hXm4pOlZE8QtDIvBNZ2WNgFAmamzJUYHGZmbXBlZy1k
|
|
||||||
ZXZlbEBmZm1wZWcub3JnAAoJELQyLwTWdljYZP8H/27rVRh4/NOvhP5JN2FhhWfo
|
|
||||||
BmAYgHWLag3a8P4yShGGgxhLjnd7LKOdSTIOb67Q7CgqzsQCV7c+VgUp068uhCod
|
|
||||||
J0TgnefWzw+iR3zupKEVRoFEsy/3A5RWXVWx42B7WTpkkShQWXaPHvUdH9ELwwfK
|
|
||||||
mq3TQMygmjjzDIa677i3uNUrb2CGyxdUXqGzmatUfrtXm0/mqUtz41neS5tuLQn5
|
|
||||||
xXcpmtsElkLK4ZaQWRC8w6emEyx49MqyRw7tTjIh/lPN+KTBUtcrYgDeCJt25H9s
|
|
||||||
2Hm9Obax0z2fPi71eP7GkbVXrGmwL1DcSegFW+TCW5CniWkWaWKe4+qDMepPtIo=
|
|
||||||
=byXw
|
|
||||||
-----END PGP SIGNATURE-----
|
|
BIN
ffmpeg-4.4.6.tar.xz
(Stored with Git LFS)
Normal file
BIN
ffmpeg-4.4.6.tar.xz
(Stored with Git LFS)
Normal file
Binary file not shown.
11
ffmpeg-4.4.6.tar.xz.asc
Normal file
11
ffmpeg-4.4.6.tar.xz.asc
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
-----BEGIN PGP SIGNATURE-----
|
||||||
|
|
||||||
|
iQFMBAABCgA2FiEE/PmG6hXm4pOlZE8QtDIvBNZ2WNgFAmgom1oYHGZmbXBlZy1k
|
||||||
|
ZXZlbEBmZm1wZWcub3JnAAoJELQyLwTWdljYtS0H/3h3yGALOlSSjBmZq/+wfw0k
|
||||||
|
QrgDVTSzILA2xnhPq4d9b6JxcaiJFX2wweid0/JxTwOE8Ky0cU+ErArlmyB1OpNl
|
||||||
|
KNzy0MXgPHV3X39Tnzgytl8nQSei2aAtg1asOscV6Lwp4e76VQOu2atLHenXq7n7
|
||||||
|
xSxCqJG65opWi2yRvS89F7PmdF3VDeYNJGaukF4Lunq4OsOa/sybe45pfd/uhC/F
|
||||||
|
aAh/64/U2mhGzl2q1rdv6WIeTxtRpT+umLuUU93g20gk8Y4L3fmwbWx9UxIjUw0X
|
||||||
|
A16PQgDw7LmmTxS4NE9cHcTwCGtUvv7ajJs6oj2fPVGScLCLInLc1KkGGkSIqqE=
|
||||||
|
=sHXx
|
||||||
|
-----END PGP SIGNATURE-----
|
@@ -1,3 +1,26 @@
|
|||||||
|
-------------------------------------------------------------------
|
||||||
|
Fri May 30 14:28:05 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
|
- Add ffmpeg-4-CVE-2024-36618.patch:
|
||||||
|
Backport 7a089ed8 from upstream, avformat/avidec: Fix integer
|
||||||
|
overflow iff ULONG_MAX < INT64_MAX.
|
||||||
|
(CVE-2024-36618, bsc#1234020)
|
||||||
|
|
||||||
|
-------------------------------------------------------------------
|
||||||
|
Thu May 29 20:43:43 UTC 2025 - Jan Engelhardt <jengelh@inai.de>
|
||||||
|
|
||||||
|
- Update to release 4.4.6
|
||||||
|
* lavc/libx265: unbreak build for X265_BUILD >= 210
|
||||||
|
* ARM: vp9mc: Load only 12 pixels in the 4 pixel wide
|
||||||
|
horizontal filter
|
||||||
|
* rtmpproto: Avoid rare crashes in the `fail:` codepath in
|
||||||
|
rtmp_open
|
||||||
|
* avcodec/snow: Fix off by 1 error in run_buffer
|
||||||
|
* avcodec/mpegvideo_enc: Check FLV1 resolution limits
|
||||||
|
- Delete ffmpeg-CVE-2023-49502.patch,
|
||||||
|
0001-libavcodec-arm-mlpdsp_armv5te-fix-label-format-to-wo.patch,
|
||||||
|
ffmpeg-4-CVE-2025-0518.patch, ffmpeg-4-CVE-2025-22919.patch (merged)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
Wed Mar 5 09:46:09 UTC 2025 - Jan Engelhardt <jengelh@inai.de>
|
Wed Mar 5 09:46:09 UTC 2025 - Jan Engelhardt <jengelh@inai.de>
|
||||||
|
|
||||||
@@ -8,7 +31,7 @@ Wed Mar 5 09:46:09 UTC 2025 - Jan Engelhardt <jengelh@inai.de>
|
|||||||
Fri Feb 19 05:17:22 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
Fri Feb 19 05:17:22 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2025-22921.patch:
|
- Add ffmpeg-4-CVE-2025-22921.patch:
|
||||||
Backporting 7f9c7f98 from upstream, clear array length when
|
Backport 7f9c7f98 from upstream, clear array length when
|
||||||
freeing it.
|
freeing it.
|
||||||
(CVE-2025-22921, bsc#1237382)
|
(CVE-2025-22921, bsc#1237382)
|
||||||
|
|
||||||
@@ -16,7 +39,7 @@ Fri Feb 19 05:17:22 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
|||||||
Fri Feb 19 04:27:06 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
Fri Feb 19 04:27:06 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2025-25473.patch:
|
- Add ffmpeg-4-CVE-2025-25473.patch:
|
||||||
Backporting c08d3004 from upstream, clear FFFormatContext packet.
|
Backport c08d3004 from upstream, clear FFFormatContext packet.
|
||||||
When packet_buffer is used in mux.c, and if a muxing process fails
|
When packet_buffer is used in mux.c, and if a muxing process fails
|
||||||
at a point where packets remained in said queue.
|
at a point where packets remained in said queue.
|
||||||
(CVE-2025-25473, bsc#1237351)
|
(CVE-2025-25473, bsc#1237351)
|
||||||
@@ -25,7 +48,7 @@ Fri Feb 19 04:27:06 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
|||||||
Fri Feb 19 03:18:02 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
Fri Feb 19 03:18:02 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2025-0518.patch:
|
- Add ffmpeg-4-CVE-2025-0518.patch:
|
||||||
Backporting b5b6391d from upstream, fixes memory data leak when
|
Backport b5b6391d from upstream, fixes memory data leak when
|
||||||
use sscanf().
|
use sscanf().
|
||||||
(CVE-2025-0518, bsc#1236007)
|
(CVE-2025-0518, bsc#1236007)
|
||||||
|
|
||||||
@@ -33,7 +56,7 @@ Fri Feb 19 03:18:02 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
|||||||
Fri Feb 19 02:58:01 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
Fri Feb 19 02:58:01 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2025-22919.patch:
|
- Add ffmpeg-4-CVE-2025-22919.patch:
|
||||||
Backporting 1446e37d from upstream, check for valid sample rate
|
Backport 1446e37d from upstream, check for valid sample rate
|
||||||
As the sample rate <= 0 is invalid.
|
As the sample rate <= 0 is invalid.
|
||||||
(CVE-2025-22919, bsc#1237371)
|
(CVE-2025-22919, bsc#1237371)
|
||||||
|
|
||||||
@@ -41,7 +64,7 @@ Fri Feb 19 02:58:01 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
|||||||
Fri Feb 19 01:48:22 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
Fri Feb 19 01:48:22 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2024-12361.patch:
|
- Add ffmpeg-4-CVE-2024-12361.patch:
|
||||||
Backporting 4065ff69 from upstream, add check for av_packet_new_side_data()
|
Backport 4065ff69 from upstream, add check for av_packet_new_side_data()
|
||||||
to avoid null pointer dereference if allocation fails.
|
to avoid null pointer dereference if allocation fails.
|
||||||
(CVE-2024-12361, bsc#1237358)
|
(CVE-2024-12361, bsc#1237358)
|
||||||
|
|
||||||
@@ -49,7 +72,7 @@ Fri Feb 19 01:48:22 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
|||||||
Fri Feb 19 01:11:17 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
Fri Feb 19 01:11:17 UTC 2025 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2024-35368.patch:
|
- Add ffmpeg-4-CVE-2024-35368.patch:
|
||||||
Backporting 45133009 from upstream, After having created the
|
Backport 45133009 from upstream, After having created the
|
||||||
AVBuffer that is put into frame->buf[0], ownership of several
|
AVBuffer that is put into frame->buf[0], ownership of several
|
||||||
objects Fix double-free on the AVFrame is unreferenced.
|
objects Fix double-free on the AVFrame is unreferenced.
|
||||||
(CVE-2024-35368, bsc#1234028)
|
(CVE-2024-35368, bsc#1234028)
|
||||||
@@ -62,6 +85,8 @@ Mon Jan 6 11:53:32 UTC 2025 - Jan Engelhardt <jengelh@inai.de>
|
|||||||
Fixes: 51896/clusterfuzz-testcase-minimized-ffmpeg_dem_DXA_fuzzer-5730576523198464
|
Fixes: 51896/clusterfuzz-testcase-minimized-ffmpeg_dem_DXA_fuzzer-5730576523198464
|
||||||
Fixes: signed integer overflow: 2147483566 + 82 cannot be represented in type 'int'
|
Fixes: signed integer overflow: 2147483566 + 82 cannot be represented in type 'int'
|
||||||
(CVE-2024-36613, bsc#1235092)
|
(CVE-2024-36613, bsc#1235092)
|
||||||
|
avformat/cafdec: dont seek beyond 64bit (CVE-2024-36617, bsc#1234019).
|
||||||
|
avformat/westwood_vqa: Fix 2g packets (CVE-2024-36616, bsc#1234018).
|
||||||
- Delete
|
- Delete
|
||||||
0001-avcodec-libsvtav1-remove-compressed_ten_bit_format-a.patch
|
0001-avcodec-libsvtav1-remove-compressed_ten_bit_format-a.patch
|
||||||
0001-avcodec-x86-mathops-clip-constants-used-with-shift-i.patch
|
0001-avcodec-x86-mathops-clip-constants-used-with-shift-i.patch
|
||||||
@@ -83,7 +108,7 @@ Tue Oct 15 08:18:54 UTC 2024 - Antonio Larrosa <alarrosa@suse.com>
|
|||||||
Fri Sep 6 15:06:21 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
Fri Sep 6 15:06:21 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2024-7055.patch:
|
- Add ffmpeg-4-CVE-2024-7055.patch:
|
||||||
Backporting 3faadbe2 from upstream, Use 64bit for input size check,
|
Backport 3faadbe2 from upstream, Use 64bit for input size check,
|
||||||
Fixes: out of array read, Fixes: poc3.
|
Fixes: out of array read, Fixes: poc3.
|
||||||
(CVE-2024-7055, bsc#1229026)
|
(CVE-2024-7055, bsc#1229026)
|
||||||
|
|
||||||
@@ -103,14 +128,14 @@ Fri Jul 26 13:19:42 UTC 2024 - Filip Kastl <filip.kastl@suse.com>
|
|||||||
Tue Jul 2 12:26:28 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
Tue Jul 2 12:26:28 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-4-CVE-2024-32230.patch:
|
- Add ffmpeg-4-CVE-2024-32230.patch:
|
||||||
Backporting 96449cfe from upstream, Fix 1 line and one column images.
|
Backport 96449cfe from upstream, Fix 1 line and one column images.
|
||||||
(CVE-2024-32230, bsc#1227296)
|
(CVE-2024-32230, bsc#1227296)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
Tue Apr 27 11:38:35 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
Tue Apr 27 11:38:35 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-CVE-2023-50010.patch:
|
- Add ffmpeg-CVE-2023-50010.patch:
|
||||||
Backporting e4d2666b from upstream, fixes the out of array access.
|
Backport e4d2666b from upstream, fixes the out of array access.
|
||||||
(CVE-2023-50010, bsc#1223256)
|
(CVE-2023-50010, bsc#1223256)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
@@ -123,14 +148,14 @@ Fri Apr 26 22:16:48 UTC 2024 - Jan Engelhardt <jengelh@inai.de>
|
|||||||
Thu Apr 23 16:14:18 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
Thu Apr 23 16:14:18 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-CVE-2023-51793.patch:
|
- Add ffmpeg-CVE-2023-51793.patch:
|
||||||
Backporting 0ecc1f0e from upstream, Fix odd height handling.
|
Backport 0ecc1f0e from upstream, Fix odd height handling.
|
||||||
(CVE-2023-51793, bsc#1223272)
|
(CVE-2023-51793, bsc#1223272)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
Thu Apr 23 15:35:32 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
Thu Apr 23 15:35:32 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-CVE-2023-49502.patch:
|
- Add ffmpeg-CVE-2023-49502.patch:
|
||||||
Backporting 737ede40 from upstream, account for chroma sub-sampling
|
Backport 737ede40 from upstream, account for chroma sub-sampling
|
||||||
in min size calculation.
|
in min size calculation.
|
||||||
(CVE-2023-49502, bsc#1223235)
|
(CVE-2023-49502, bsc#1223235)
|
||||||
|
|
||||||
@@ -138,14 +163,14 @@ Thu Apr 23 15:35:32 UTC 2024 - Cliff Zhao <qzhao@suse.com>
|
|||||||
Tue Apr 23 14:25:53 UTC 2024 - Jan Engelhardt <jengelh@inai.de>
|
Tue Apr 23 14:25:53 UTC 2024 - Jan Engelhardt <jengelh@inai.de>
|
||||||
|
|
||||||
- Add 0001-avfilter-vf_minterpolate-Check-pts-before-division.patch:
|
- Add 0001-avfilter-vf_minterpolate-Check-pts-before-division.patch:
|
||||||
Backporting 68146f06 from upstream, Check pts before division.
|
Backport 68146f06 from upstream, Check pts before division.
|
||||||
(CVE-2023-51798, bsc#1223304)
|
(CVE-2023-51798, bsc#1223304)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
Mon Apr 22 12:41:55 UTC 2024 - Jan Engelhardt <jengelh@inai.de>
|
Mon Apr 22 12:41:55 UTC 2024 - Jan Engelhardt <jengelh@inai.de>
|
||||||
|
|
||||||
- Add 0001-avutil-hwcontext-Don-t-assume-frames_uninit-is-reent.patch:
|
- Add 0001-avutil-hwcontext-Don-t-assume-frames_uninit-is-reent.patch:
|
||||||
Backporting 76a48e85 from upstream, Check length.
|
Backport 76a48e85 from upstream, Check length.
|
||||||
(CVE-2024-31578, bsc#1223070)
|
(CVE-2024-31578, bsc#1223070)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
@@ -187,7 +212,7 @@ Wed Dec 6 08:50:00 UTC 2023 - Jan Engelhardt <jengelh@inai.de>
|
|||||||
Fri Nov 3 08:17:13 UTC 2023 - Marcus Meissner <meissner@suse.com>
|
Fri Nov 3 08:17:13 UTC 2023 - Marcus Meissner <meissner@suse.com>
|
||||||
|
|
||||||
- Add ffmpeg-fix-new-binutils.patch:
|
- Add ffmpeg-fix-new-binutils.patch:
|
||||||
Backporting 01fc3034 from upstream, Fix build with new binutils
|
Backport 01fc3034 from upstream, Fix build with new binutils
|
||||||
(bsc#1215309)
|
(bsc#1215309)
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
@@ -318,6 +343,7 @@ Mon Oct 10 11:18:30 UTC 2022 - Bjørn Lie <bjorn.lie@gmail.com>
|
|||||||
|
|
||||||
- Update to version 4.4.3:
|
- Update to version 4.4.3:
|
||||||
* Stable bug fix release, mainly codecs, filter and format fixes.
|
* Stable bug fix release, mainly codecs, filter and format fixes.
|
||||||
|
* configure: extend SDL check to accept all 2.x versions (boo#12263080).
|
||||||
- Drop ffmpeg-sdl2-detection.patch: Fixed upstream.
|
- Drop ffmpeg-sdl2-detection.patch: Fixed upstream.
|
||||||
- Refresh patches with quilt:
|
- Refresh patches with quilt:
|
||||||
* ffmpeg-libglslang-detection.patch
|
* ffmpeg-libglslang-detection.patch
|
||||||
@@ -699,6 +725,7 @@ Tue Aug 6 15:35:35 UTC 2019 - Ismail Dönmez <idonmez@suse.com>
|
|||||||
* mov muxer writes tracks with unspecified language instead
|
* mov muxer writes tracks with unspecified language instead
|
||||||
of English by default
|
of English by default
|
||||||
* added support for using clang to compile CUDA kernels
|
* added support for using clang to compile CUDA kernels
|
||||||
|
* avcodec/g729_parser: Check channels (CVE-2022-1475, bsc#1198898)
|
||||||
- Drop ffmpeg-avcodec-libdav1d-AV1-decoder-wrapper.patch, merged
|
- Drop ffmpeg-avcodec-libdav1d-AV1-decoder-wrapper.patch, merged
|
||||||
upstream.
|
upstream.
|
||||||
- Rebase and rename
|
- Rebase and rename
|
||||||
@@ -903,7 +930,6 @@ Tue Nov 06 01:39:11 UTC 2018 - sean@suspend.net
|
|||||||
remove cve-2017-17555.diff (fixed upstream).
|
remove cve-2017-17555.diff (fixed upstream).
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
|
|
||||||
Sat Nov 03 14:48:35 UTC 2018 - sean@suspend.net
|
Sat Nov 03 14:48:35 UTC 2018 - sean@suspend.net
|
||||||
|
|
||||||
- Remove 0001-avformat-fivenc-Check-audio-packet-size.patch (fixed upstream (bsc#8591d16)
|
- Remove 0001-avformat-fivenc-Check-audio-packet-size.patch (fixed upstream (bsc#8591d16)
|
||||||
|
@@ -108,7 +108,7 @@
|
|||||||
%define _major_version 4
|
%define _major_version 4
|
||||||
%define _major_expected 5
|
%define _major_expected 5
|
||||||
Name: ffmpeg-4
|
Name: ffmpeg-4
|
||||||
Version: 4.4.5
|
Version: 4.4.6
|
||||||
Release: 0
|
Release: 0
|
||||||
Summary: Set of libraries for working with various multimedia formats
|
Summary: Set of libraries for working with various multimedia formats
|
||||||
License: GPL-3.0-or-later
|
License: GPL-3.0-or-later
|
||||||
@@ -135,16 +135,13 @@ Patch11: ffmpeg-libglslang-detection.patch
|
|||||||
Patch14: ffmpeg-glslang-cxx17.patch
|
Patch14: ffmpeg-glslang-cxx17.patch
|
||||||
Patch15: 0001-avutil-hwcontext-Don-t-assume-frames_uninit-is-reent.patch
|
Patch15: 0001-avutil-hwcontext-Don-t-assume-frames_uninit-is-reent.patch
|
||||||
Patch16: 0001-avcodec-libsvtav1-unbreak-build-with-latest-svtav1.patch
|
Patch16: 0001-avcodec-libsvtav1-unbreak-build-with-latest-svtav1.patch
|
||||||
Patch17: ffmpeg-CVE-2023-49502.patch
|
|
||||||
Patch22: ffmpeg-c99.patch
|
Patch22: ffmpeg-c99.patch
|
||||||
Patch23: 0001-libavcodec-arm-mlpdsp_armv5te-fix-label-format-to-wo.patch
|
|
||||||
Patch24: ffmpeg-4-CVE-2024-35368.patch
|
Patch24: ffmpeg-4-CVE-2024-35368.patch
|
||||||
Patch25: ffmpeg-4-CVE-2024-12361.patch
|
Patch25: ffmpeg-4-CVE-2024-12361.patch
|
||||||
Patch26: ffmpeg-4-CVE-2025-22919.patch
|
|
||||||
Patch27: ffmpeg-4-CVE-2025-0518.patch
|
|
||||||
Patch28: ffmpeg-4-CVE-2025-25473.patch
|
Patch28: ffmpeg-4-CVE-2025-25473.patch
|
||||||
Patch29: ffmpeg-4-CVE-2025-22921.patch
|
Patch29: ffmpeg-4-CVE-2025-22921.patch
|
||||||
Patch30: ffmpeg-avcodec-libdav1d-don-t-repeatedly-parse-the-same-seq.patch
|
Patch30: ffmpeg-avcodec-libdav1d-don-t-repeatedly-parse-the-same-seq.patch
|
||||||
|
Patch31: ffmpeg-4-CVE-2024-36618.patch
|
||||||
BuildRequires: ladspa-devel
|
BuildRequires: ladspa-devel
|
||||||
BuildRequires: libgsm-devel
|
BuildRequires: libgsm-devel
|
||||||
BuildRequires: libmp3lame-devel
|
BuildRequires: libmp3lame-devel
|
||||||
|
@@ -1,43 +0,0 @@
|
|||||||
From 737ede405b11a37fdd61d19cf25df296a0cb0b75
|
|
||||||
From: Cosmin Stejerean <cosmin@cosmin.at>
|
|
||||||
Date: Wed Dec 6 18:39:32 2023 +0800
|
|
||||||
Subject: avfilter/bwdif: account for chroma sub-sampling in min size calculation
|
|
||||||
References: https://bugzilla.opensuse.org/1223235
|
|
||||||
References: CVE-2023-49502
|
|
||||||
|
|
||||||
The current logic for detecting frames that are too small for the
|
|
||||||
algorithm does not account for chroma sub-sampling, and so a sample
|
|
||||||
where the luma plane is large enough, but the chroma planes are not
|
|
||||||
will not be rejected. In that event, a heap overflow will occur.
|
|
||||||
|
|
||||||
This change adjusts the logic to consider the chroma planes and makes
|
|
||||||
the change to all three bwdif implementations.
|
|
||||||
|
|
||||||
Fixes #10688
|
|
||||||
|
|
||||||
Signed-off-by: Cosmin Stejerean <cosmin@cosmin.at>
|
|
||||||
Reviewed-by: Thomas Mundt <tmundt75@gmail.com>
|
|
||||||
Signed-off-by: Philip Langdale <philipl@overt.org>
|
|
||||||
|
|
||||||
diff -Nura ffmpeg-4.4.4/libavfilter/vf_bwdif.c ffmpeg-4.4.4_new/libavfilter/vf_bwdif.c
|
|
||||||
--- ffmpeg-4.4.4/libavfilter/vf_bwdif.c 2023-04-13 02:01:50.000000000 +0800
|
|
||||||
+++ ffmpeg-4.4.4_new/libavfilter/vf_bwdif.c 2024-04-26 02:21:48.162806014 +0800
|
|
||||||
@@ -343,13 +343,14 @@
|
|
||||||
if(yadif->mode&1)
|
|
||||||
link->frame_rate = av_mul_q(link->src->inputs[0]->frame_rate, (AVRational){2,1});
|
|
||||||
|
|
||||||
- if (link->w < 3 || link->h < 4) {
|
|
||||||
- av_log(ctx, AV_LOG_ERROR, "Video of less than 3 columns or 4 lines is not supported\n");
|
|
||||||
+ yadif->csp = av_pix_fmt_desc_get(link->format);
|
|
||||||
+ yadif->filter = filter;
|
|
||||||
+
|
|
||||||
+ if (AV_CEIL_RSHIFT(link->w, yadif->csp->log2_chroma_w) < 3 || AV_CEIL_RSHIFT(link->h, yadif->csp->log2_chroma_h) < 4) {
|
|
||||||
+ av_log(ctx, AV_LOG_ERROR, "Video with planes less than 3 columns or 4 lines is not supported\n");
|
|
||||||
return AVERROR(EINVAL);
|
|
||||||
}
|
|
||||||
|
|
||||||
- yadif->csp = av_pix_fmt_desc_get(link->format);
|
|
||||||
- yadif->filter = filter;
|
|
||||||
if (yadif->csp->comp[0].depth > 8) {
|
|
||||||
s->filter_intra = filter_intra_16bit;
|
|
||||||
s->filter_line = filter_line_c_16bit;
|
|
Reference in New Issue
Block a user