已合并
fix CVE-2023-6604 #486
Funda Wang创建于 25 天前
fix CVE-2023-6604 #486
已合并
Funda Wang创建于 25 天前
从已删除 :fix-cve-2023-6604-sp422合入到src-openeuler/ffmpegopenEuler-22.03-LTS-SP4
共 2 个文件变更+95-1
@@ -0,0 +1,87 @@
1+From 9806a37bcf42ebd9618adb2ce4a70ce7ecd0d921 Mon Sep 17 00:00:00 2001
2+From: Funda Wang <fundawang@yeah.net>
3+Date: Thu, 11 Jul 2024 18:10:00 +0200
4+Subject: [PATCH] avformat/bintext: Check avio_size() return
5+ 
6+Fixes: CID1604503 Overflowed constant
7+Fixes: CID1604566 Overflowed constant
8+ 
9+Reference: upstream commit bf61f811e73dc62d1b53ed4ef6044b4e9e195113 (master)
10+ upstream commit 9806a37bcf42ebd9618adb2ce4a70ce7ecd0d921 (release/4.4)
11+Adapted for ffmpeg 4.2.4 (idf_read_header variable declarations differ)
12+ 
13+Co-Authored-By: AtomCode (deepseek-v4-flash) <noreply@atomgit.com>
14+---
15+ libavformat/bintext.c | 20 ++++++++++++++------
16+ 1 file changed, 20 insertions(+), 6 deletions(-)
17+ 
18+--- a/libavformat/bintext.c
19++++ b/libavformat/bintext.c
20+@@ -90,9 +90,12 @@
21+ AVIOContext *pb = avctx->pb;
22+ char buf[36];
23+ int len;
24+- uint64_t start_pos = avio_size(pb) - 256;
25++ int64_t start_pos = avio_size(pb);
26+
27+- avio_seek(pb, start_pos, SEEK_SET);
28++ if (start_pos < 256)
29++ return AVERROR_INVALIDDATA;
30++
31++ avio_seek(pb, start_pos - 256, SEEK_SET);
32+ if (avio_read(pb, buf, sizeof(next_magic)) != sizeof(next_magic))
33+ return -1;
34+ if (memcmp(buf, next_magic, sizeof(next_magic)))
35+@@ -249,7 +252,10 @@
36+ return AVERROR(EIO);
37+
38+ if (pb->seekable & AVIO_SEEKABLE_NORMAL) {
39+- bin->fsize = avio_size(pb) - 9 - st->codecpar->extradata_size;
40++ int64_t fsize = avio_size(pb);
41++ if (fsize < 9 + st->codecpar->extradata_size)
42++ return 0;
43++ bin->fsize = fsize - 9 - st->codecpar->extradata_size;
44+ ff_sauce_read(s, &bin->fsize, NULL, 0);
45+ avio_seek(pb, 9 + st->codecpar->extradata_size, SEEK_SET);
46+ }
47+@@ -288,7 +294,10 @@
48+
49+ if (pb->seekable & AVIO_SEEKABLE_NORMAL) {
50+ int got_width = 0;
51+- bin->fsize = avio_size(pb) - 1 - 192 - 4096;
52++ int64_t fsize = avio_size(pb);
53++ if (fsize < 1 + 192 + 4096)
54++ return 0;
55++ bin->fsize = fsize - 1 - 192 - 4096;
56+ st->codecpar->width = 80<<3;
57+ ff_sauce_read(s, &bin->fsize, &got_width, 0);
58+ if (!bin->width)
59+@@ -319,6 +328,7 @@
60+ AVIOContext *pb = s->pb;
61+ AVStream *st;
62+ int got_width = 0;
63++ int64_t fsize;
64+
65+ if (!(pb->seekable & AVIO_SEEKABLE_NORMAL))
66+ return AVERROR(EIO);
67+@@ -333,14 +343,18 @@
68+ st->codecpar->extradata[0] = 16;
69+ st->codecpar->extradata[1] = BINTEXT_PALETTE|BINTEXT_FONT;
70+
71+- avio_seek(pb, avio_size(pb) - 4096 - 48, SEEK_SET);
72++ fsize = avio_size(pb);
73++ if (fsize < 12 + 4096 + 48)
74++ return AVERROR_INVALIDDATA;
75++ bin->fsize = fsize - 12 - 4096 - 48;
76++
77++ avio_seek(pb, bin->fsize + 12, SEEK_SET);
78+
79+ if (avio_read(pb, st->codecpar->extradata + 2 + 48, 4096) < 0)
80+ return AVERROR(EIO);
81+ if (avio_read(pb, st->codecpar->extradata + 2, 48) < 0)
82+ return AVERROR(EIO);
83+
84+- bin->fsize = avio_size(pb) - 12 - 4096 - 48;
85+ ff_sauce_read(s, &bin->fsize, &got_width, 0);
86+ if (!bin->width)
87+ calculate_height(st->codecpar, bin->fsize);
@@ -60,7 +60,7 @@
60Summary: Digital VCR and streaming server60Summary: Digital VCR and streaming server
61Name: ffmpeg%{?flavor}61Name: ffmpeg%{?flavor}
62Version: 4.2.462Version: 4.2.4
63-Release: 5563+Release: 56
64License: %{ffmpeg_license}64License: %{ffmpeg_license}
65URL: http://ffmpeg.org/65URL: http://ffmpeg.org/
66%if 0%{?date}66%if 0%{?date}
@@ -161,6 +161,7 @@ Patch89: CVE-2026-38346.patch
161Patch90: CVE-2026-38347.patch161Patch90: CVE-2026-38347.patch
162Patch91: CVE-2026-38348.patch162Patch91: CVE-2026-38348.patch
163Patch92: CVE-2026-38349.patch163Patch92: CVE-2026-38349.patch
164+Patch93: CVE-2023-6604.patch
164 165 
165Requires: %{name}-libs%{?_isa} = %{version}-%{release}166Requires: %{name}-libs%{?_isa} = %{version}-%{release}
166%{?_with_cuda:BuildRequires: cuda-minimal-build-%{_cuda_version_rpm} cuda-drivers-devel}167%{?_with_cuda:BuildRequires: cuda-minimal-build-%{_cuda_version_rpm} cuda-drivers-devel}
@@ -494,6 +495,12 @@ install -pm755 tools/qt-faststart %{buildroot}%{_bindir}
494 495 
495 496 
496%changelog497%changelog
498+* Thu Sep 4 2026 Funda Wang <fundawang@yeah.net> - 4.2.4-56
499+- Type: CVE
500+- ID: CVE-2023-6604
501+- SUG: NA
502+- DESC: fix CVE-2023-6604 (XBIN demuxer DoS amplification: arbitrary data demuxed as XBIN without format validation, causing unexpected CPU load and storage consumption)
503+ 
497* Sun Aug 30 2026 Funda Wang <fundawang@yeah.net> - 4.2.4-55504* Sun Aug 30 2026 Funda Wang <fundawang@yeah.net> - 4.2.4-55
498- Type: CVE505- Type: CVE
499- ID: CVE-2026-18393, CVE-2026-38343, CVE-2026-38344, CVE-2026-38346, CVE-2026-38347, CVE-2026-38348, CVE-2026-38349506- ID: CVE-2026-18393, CVE-2026-38343, CVE-2026-38344, CVE-2026-38346, CVE-2026-38347, CVE-2026-38348, CVE-2026-38349