[vlc-commits] [Git][videolan/vlc][master] demux: avi: add recursion limit

François Cartegnie (@fcartegnie) gitlab at videolan.org
Mon Sep 14 03:43:54 UTC 2026



François Cartegnie pushed to branch master at VideoLAN / VLC


Commits:
4f411065 by François Cartegnie at 2026-09-14T05:33:25+02:00
demux: avi: add recursion limit

refs #30101

- - - - -


3 changed files:

- modules/demux/avi/avi.c
- modules/demux/avi/libavi.c
- modules/demux/avi/libavi.h


Changes:

=====================================
modules/demux/avi/avi.c
=====================================
@@ -3076,7 +3076,7 @@ static void AVI_ExtractSubtitle( demux_t *p_demux,
 
     p_indx = AVI_ChunkFind( p_strl, AVIFOURCC_indx, 0, false );
     avi_chunk_t ck;
-    AVI_ChunkInit( &ck );
+    AVI_ChunkInit( &ck, p_strl->i_depth + 1 );
     int64_t  i_position;
     unsigned i_size;
     if( p_indx )


=====================================
modules/demux/avi/libavi.c
=====================================
@@ -37,6 +37,7 @@
 #endif
 
 #define __EVEN( x ) (((x) + 1) & ~1)
+#define AVI_MAX_DEPTH 32
 
 static vlc_fourcc_t GetFOURCC( const uint8_t *p_buff )
 {
@@ -59,11 +60,11 @@ static uint64_t AVI_ChunkEnd( const avi_chunk_t *p_ck )
  *
  ****************************************************************************/
 static int AVI_ChunkReadCommon( stream_t *s, avi_chunk_t *p_chk,
-                                const avi_chunk_t *p_father )
+                                const avi_chunk_t *p_father, unsigned i_depth )
 {
     const uint8_t *p_peek;
 
-    AVI_ChunkInit( p_chk );
+    AVI_ChunkInit( p_chk, i_depth );
 
     const uint64_t i_pos = vlc_stream_Tell( s );
     if( vlc_stream_Peek( s, &p_peek, 8 ) < 8 )
@@ -127,7 +128,7 @@ static int AVI_NextChunk( stream_t *s, avi_chunk_t *p_chk )
 
     if( !p_chk )
     {
-        if( AVI_ChunkReadCommon( s, &chk, NULL ) )
+        if( AVI_ChunkReadCommon( s, &chk, NULL, 0 ) )
         {
             return VLC_EGENERIC;
         }
@@ -991,13 +992,17 @@ int  AVI_ChunkRead( stream_t *s, avi_chunk_t *p_chk, avi_chunk_t *p_father )
 {
     int i_index;
 
+    unsigned i_depth = p_father ? p_father->common.i_depth + 1 : 0;
+    if( i_depth >= AVI_MAX_DEPTH )
+        return VLC_EGENERIC;
+
     if( !p_chk )
     {
         msg_Warn( s, "cannot read null chunk" );
         return VLC_EGENERIC;
     }
 
-    if( AVI_ChunkReadCommon( s, p_chk, p_father ) )
+    if( AVI_ChunkReadCommon( s, p_chk, p_father, i_depth ) )
         return VLC_EGENERIC;
 
     if( p_chk->common.i_chunk_fourcc == VLC_FOURCC( 0, 0, 0, 0 ) )
@@ -1061,14 +1066,15 @@ void AVI_ChunkClean( stream_t *s,
         msg_Warn( s, "unknown chunk: %4.4s (not unloaded)",
                 (char*)&p_chk->common.i_chunk_fourcc );
     }
-    AVI_ChunkInit( p_chk );
+    AVI_ChunkInit( p_chk, 0 );
 
     return;
 }
 
-void AVI_ChunkInit( avi_chunk_t *p_chk )
+void AVI_ChunkInit( avi_chunk_t *p_chk, unsigned i_depth )
 {
     memset( p_chk, 0, sizeof(*p_chk) );
+    p_chk->common.i_depth = i_depth;
 }
 
 static void AVI_ChunkDumpDebug_level( vlc_object_t *p_obj,
@@ -1129,6 +1135,7 @@ int AVI_ChunkReadRoot( stream_t *s, avi_chunk_t *p_root )
     p_list->p_father = NULL;
     p_list->p_next  = NULL;
     p_list->p_first = NULL;
+    p_list->i_depth = 0;
 
     p_list->i_type = VLC_FOURCC( 'r', 'o', 'o', 't' );
 


=====================================
modules/demux/avi/libavi.h
=====================================
@@ -48,7 +48,8 @@ typedef union avi_chunk_u avi_chunk_t;
     uint64_t i_chunk_pos;          \
     avi_chunk_t *p_next;           \
     avi_chunk_t *p_father;         \
-    avi_chunk_t *p_first;
+    avi_chunk_t *p_first; \
+    unsigned i_depth;
 
 #define AVI_CHUNK( p_chk ) (avi_chunk_t*)(p_chk)
 
@@ -256,7 +257,7 @@ int     AVI_ChunkRead( stream_t *,
                        avi_chunk_t *p_chk,
                        avi_chunk_t *p_father );
 void    AVI_ChunkClean( stream_t *, avi_chunk_t * );
-void    AVI_ChunkInit( avi_chunk_t * );
+void    AVI_ChunkInit( avi_chunk_t *, unsigned );
 
 int     AVI_ChunkCount_( avi_chunk_t *, vlc_fourcc_t, bool );
 void   *AVI_ChunkFind_ ( avi_chunk_t *, vlc_fourcc_t, int, bool );



View it on GitLab: https://code.videolan.org/videolan/vlc/-/commit/4f411065d6ff7ec898026a7a0cf2d672b799a52b

-- 
View it on GitLab: https://code.videolan.org/videolan/vlc/-/commit/4f411065d6ff7ec898026a7a0cf2d672b799a52b
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the vlc-commits mailing list