已合并
fix CVE-2023-6604 #486
Funda Wang创建于 25 天前
fix CVE-2023-6604 #486
已合并
从已删除 :fix-cve-2023-6604-sp422合入到src-openeuler/ffmpegopenEuler-22.03-LTS-SP4
共 2 个文件变更+95-1
| @@ -0,0 +1,87 @@ | |||
| 1 | +From 9806a37bcf42ebd9618adb2ce4a70ce7ecd0d921 Mon Sep 17 00:00:00 2001 | ||
| 2 | +From: Funda Wang <fundawang@yeah.net> | ||
| 3 | +Date: Thu, 11 Jul 2024 18:10:00 +0200 | ||
| 4 | +Subject: [PATCH] avformat/bintext: Check avio_size() return | ||
| 5 | + | ||
| 6 | +Fixes: CID1604503 Overflowed constant | ||
| 7 | +Fixes: CID1604566 Overflowed constant | ||
| 8 | + | ||
| 9 | +Reference: upstream commit bf61f811e73dc62d1b53ed4ef6044b4e9e195113 (master) | ||
| 10 | + upstream commit 9806a37bcf42ebd9618adb2ce4a70ce7ecd0d921 (release/4.4) | ||
| 11 | +Adapted for ffmpeg 4.2.4 (idf_read_header variable declarations differ) | ||
| 12 | + | ||
| 13 | +Co-Authored-By: AtomCode (deepseek-v4-flash) <noreply@atomgit.com> | ||
| 14 | +--- | ||
| 15 | + libavformat/bintext.c | 20 ++++++++++++++------ | ||
| 16 | + 1 file changed, 20 insertions(+), 6 deletions(-) | ||
| 17 | + | ||
| 18 | +--- a/libavformat/bintext.c | ||
| 19 | ++++ b/libavformat/bintext.c | ||
| 20 | + | ||
| 21 | + AVIOContext *pb = avctx->pb; | ||
| 22 | + char buf[36]; | ||
| 23 | + int len; | ||
| 24 | +- uint64_t start_pos = avio_size(pb) - 256; | ||
| 25 | ++ int64_t start_pos = avio_size(pb); | ||
| 26 | + | ||
| 27 | +- avio_seek(pb, start_pos, SEEK_SET); | ||
| 28 | ++ if (start_pos < 256) | ||
| 29 | ++ return AVERROR_INVALIDDATA; | ||
| 30 | ++ | ||
| 31 | ++ avio_seek(pb, start_pos - 256, SEEK_SET); | ||
| 32 | + if (avio_read(pb, buf, sizeof(next_magic)) != sizeof(next_magic)) | ||
| 33 | + return -1; | ||
| 34 | + if (memcmp(buf, next_magic, sizeof(next_magic))) | ||
| 35 | + | ||
| 36 | + return AVERROR(EIO); | ||
| 37 | + | ||
| 38 | + if (pb->seekable & AVIO_SEEKABLE_NORMAL) { | ||
| 39 | +- bin->fsize = avio_size(pb) - 9 - st->codecpar->extradata_size; | ||
| 40 | ++ int64_t fsize = avio_size(pb); | ||
| 41 | ++ if (fsize < 9 + st->codecpar->extradata_size) | ||
| 42 | ++ return 0; | ||
| 43 | ++ bin->fsize = fsize - 9 - st->codecpar->extradata_size; | ||
| 44 | + ff_sauce_read(s, &bin->fsize, NULL, 0); | ||
| 45 | + avio_seek(pb, 9 + st->codecpar->extradata_size, SEEK_SET); | ||
| 46 | + } | ||
| 47 | + | ||
| 48 | + | ||
| 49 | + if (pb->seekable & AVIO_SEEKABLE_NORMAL) { | ||
| 50 | + int got_width = 0; | ||
| 51 | +- bin->fsize = avio_size(pb) - 1 - 192 - 4096; | ||
| 52 | ++ int64_t fsize = avio_size(pb); | ||
| 53 | ++ if (fsize < 1 + 192 + 4096) | ||
| 54 | ++ return 0; | ||
| 55 | ++ bin->fsize = fsize - 1 - 192 - 4096; | ||
| 56 | + st->codecpar->width = 80<<3; | ||
| 57 | + ff_sauce_read(s, &bin->fsize, &got_width, 0); | ||
| 58 | + if (!bin->width) | ||
| 59 | + | ||
| 60 | + AVIOContext *pb = s->pb; | ||
| 61 | + AVStream *st; | ||
| 62 | + int got_width = 0; | ||
| 63 | ++ int64_t fsize; | ||
| 64 | + | ||
| 65 | + if (!(pb->seekable & AVIO_SEEKABLE_NORMAL)) | ||
| 66 | + return AVERROR(EIO); | ||
| 67 | + | ||
| 68 | + st->codecpar->extradata[0] = 16; | ||
| 69 | + st->codecpar->extradata[1] = BINTEXT_PALETTE|BINTEXT_FONT; | ||
| 70 | + | ||
| 71 | +- avio_seek(pb, avio_size(pb) - 4096 - 48, SEEK_SET); | ||
| 72 | ++ fsize = avio_size(pb); | ||
| 73 | ++ if (fsize < 12 + 4096 + 48) | ||
| 74 | ++ return AVERROR_INVALIDDATA; | ||
| 75 | ++ bin->fsize = fsize - 12 - 4096 - 48; | ||
| 76 | ++ | ||
| 77 | ++ avio_seek(pb, bin->fsize + 12, SEEK_SET); | ||
| 78 | + | ||
| 79 | + if (avio_read(pb, st->codecpar->extradata + 2 + 48, 4096) < 0) | ||
| 80 | + return AVERROR(EIO); | ||
| 81 | + if (avio_read(pb, st->codecpar->extradata + 2, 48) < 0) | ||
| 82 | + return AVERROR(EIO); | ||
| 83 | + | ||
| 84 | +- bin->fsize = avio_size(pb) - 12 - 4096 - 48; | ||
| 85 | + ff_sauce_read(s, &bin->fsize, &got_width, 0); | ||
| 86 | + if (!bin->width) | ||
| 87 | + calculate_height(st->codecpar, bin->fsize); | ||
| @@ -60,7 +60,7 @@ | |||
| 60 | Summary: Digital VCR and streaming server | 60 | Summary: Digital VCR and streaming server |
| 61 | Name: ffmpeg%{?flavor} | 61 | Name: ffmpeg%{?flavor} |
| 62 | Version: 4.2.4 | 62 | Version: 4.2.4 |
| 63 | -Release: 55 | 63 | +Release: 56 |
| 64 | License: %{ffmpeg_license} | 64 | License: %{ffmpeg_license} |
| 65 | URL: http://ffmpeg.org/ | 65 | URL: http://ffmpeg.org/ |
| 66 | %if 0%{?date} | 66 | %if 0%{?date} |
| @@ -161,6 +161,7 @@ Patch89: CVE-2026-38346.patch | |||
| 161 | Patch90: CVE-2026-38347.patch | 161 | Patch90: CVE-2026-38347.patch |
| 162 | Patch91: CVE-2026-38348.patch | 162 | Patch91: CVE-2026-38348.patch |
| 163 | Patch92: CVE-2026-38349.patch | 163 | Patch92: CVE-2026-38349.patch |
| 164 | +Patch93: CVE-2023-6604.patch | ||
| 164 | 165 | ||
| 165 | Requires: %{name}-libs%{?_isa} = %{version}-%{release} | 166 | Requires: %{name}-libs%{?_isa} = %{version}-%{release} |
| 166 | %{?_with_cuda:BuildRequires: cuda-minimal-build-%{_cuda_version_rpm} cuda-drivers-devel} | 167 | %{?_with_cuda:BuildRequires: cuda-minimal-build-%{_cuda_version_rpm} cuda-drivers-devel} |
| @@ -494,6 +495,12 @@ install -pm755 tools/qt-faststart %{buildroot}%{_bindir} | |||
| 494 | 495 | ||
| 495 | 496 | ||
| 496 | %changelog | 497 | %changelog |
| 498 | +* Thu Sep 4 2026 Funda Wang <fundawang@yeah.net> - 4.2.4-56 | ||
| 499 | +- Type: CVE | ||
| 500 | +- ID: CVE-2023-6604 | ||
| 501 | +- SUG: NA | ||
| 502 | +- DESC: fix CVE-2023-6604 (XBIN demuxer DoS amplification: arbitrary data demuxed as XBIN without format validation, causing unexpected CPU load and storage consumption) | ||
| 503 | + | ||
| 497 | * Sun Aug 30 2026 Funda Wang <fundawang@yeah.net> - 4.2.4-55 | 504 | * Sun Aug 30 2026 Funda Wang <fundawang@yeah.net> - 4.2.4-55 |
| 498 | - Type: CVE | 505 | - Type: CVE |
| 499 | - ID: CVE-2026-18393, CVE-2026-38343, CVE-2026-38344, CVE-2026-38346, CVE-2026-38347, CVE-2026-38348, CVE-2026-38349 | 506 | - ID: CVE-2026-18393, CVE-2026-38343, CVE-2026-38344, CVE-2026-38346, CVE-2026-38347, CVE-2026-38348, CVE-2026-38349 |