[vlc-commits] [Git][videolan/vlc][master] 4 commits: demux: mxpeg_helper: only increment base offset after reads

François Cartegnie (@fcartegnie) gitlab at videolan.org
Sat Sep 19 09:03:08 UTC 2026



François Cartegnie pushed to branch master at VideoLAN / VLC


Commits:
54312d30 by François Cartegnie at 2026-09-19T10:52:22+02:00
demux: mxpeg_helper: only increment base offset after reads

readability

- - - - -
3313acba by François Cartegnie at 2026-09-19T10:52:22+02:00
demux: image: fix segfault in IsMxpeg()

refs #29638

- - - - -
d13f76cc by François Cartegnie at 2026-09-19T10:52:22+02:00
demux: mpeg_helper: avoid overflow in comparison

- - - - -
b0475ab0 by François Cartegnie at 2026-09-19T10:52:22+02:00
demux: mxpeg_helper: early check peek

otherwise it tried to match uninitialized data

- - - - -


1 changed file:

- modules/demux/mxpeg_helper.h


Changes:

=====================================
modules/demux/mxpeg_helper.h
=====================================
@@ -43,6 +43,8 @@ static bool IsMxpeg(stream_t *s)
 {
     const uint8_t *header;
     int size = vlc_stream_Peek(s, &header, 256);
+    if(unlikely(size < 8))
+        return false;
     int position = 0;
 
     if (find_jpeg_marker(&position, header, size) != 0xd8 || position > size-2)
@@ -50,7 +52,7 @@ static bool IsMxpeg(stream_t *s)
     if (find_jpeg_marker(&position, header, position + 2) != 0xe0)
         return false;
 
-    if (position + 2 > size)
+    if (position > size - 2)
         return false;
 
     /* Skip this jpeg header */
@@ -58,34 +60,32 @@ static bool IsMxpeg(stream_t *s)
     position += header_size;
 
     /* Get enough data to analyse the next header */
-    if (position + 6 > size)
+    if (position + 8 > size)
     {
-        size = position + 6;
+        size = position + 8;
         if( vlc_stream_Peek (s, &header, size) < size )
             return false;
     }
 
     if ( !(header[position] == 0xFF && header[position+1] == 0xFE) )
         return false;
-    position += 2;
-    header_size = GetWBE (&header[position]);
+
+    header_size = GetWBE (&header[position+2]);
 
     /* Check if this is a MXF header. We may have a jpeg comment first */
-    if (!memcmp (&header[position+2], "MXF\0", 4) )
+    if (!memcmp (&header[position+4], "MXF\0", 4) )
         return true;
 
     /* Skip the jpeg comment and find the MXF header after that */
-    size = position + header_size + 8; //8 = FF FE 00 00 M X F 00
+    size = position + 2 + header_size + 8; //8 = FF FE 00 00 M X F 00
     if (vlc_stream_Peek(s, &header, size ) < size)
         return false;
 
-    position += header_size;
+    position += 2 + header_size;
     if ( !(header[position] == 0xFF && header[position+1] == 0xFE) )
         return false;
 
-    position += 4;
-
-    if (memcmp (&header[position], "MXF\0", 4) )
+    if (memcmp (&header[position + 4], "MXF\0", 4) )
         return false;
 
     return true;



View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/7bfe24d309f3cb8cbf97e5770db83c02c667aedd...b0475ab0f7d791230246b161172b83b6c2920ead

-- 
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/7bfe24d309f3cb8cbf97e5770db83c02c667aedd...b0475ab0f7d791230246b161172b83b6c2920ead
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the vlc-commits mailing list