[vlc-commits] [Git][videolan/vlc][3.0.x] 4 commits: demux: mxpeg_helper: only increment base offset after reads
François Cartegnie (@fcartegnie)
gitlab at videolan.org
Thu Sep 24 11:34:42 UTC 2026
François Cartegnie pushed to branch 3.0.x at VideoLAN / VLC
Commits:
064163b7 by François Cartegnie at 2026-09-24T13:28:01+02:00
demux: mxpeg_helper: only increment base offset after reads
readability
(cherry picked from commit 632f24dd6b46e2535d0d20ef1ac4d8b60c4535f9)
- - - - -
04e8b515 by François Cartegnie at 2026-09-24T13:28:01+02:00
demux: image: fix segfault in IsMxpeg()
refs #29638
(cherry picked from commit a547e3b51ea6b51aff8c91431c903f01b2061852)
- - - - -
4ef678c0 by François Cartegnie at 2026-09-24T13:28:01+02:00
demux: mpeg_helper: avoid overflow in comparison
(cherry picked from commit 2b13166445e71489888d91e60ef8faf5fd690b8a)
- - - - -
055db45c by François Cartegnie at 2026-09-24T13:28:01+02:00
demux: mxpeg_helper: early check peek
otherwise it tried to match uninitialized data
(cherry picked from commit 51bbf4bad0fda0f0baea85bfec06410ec9a57c1b)
- - - - -
1 changed file:
- modules/demux/mxpeg_helper.h
Changes:
=====================================
modules/demux/mxpeg_helper.h
=====================================
@@ -44,6 +44,8 @@ static bool IsMxpeg(stream_t *s)
{
const uint8_t *header;
int size = vlc_stream_Peek(s, &header, 256);
+ if(unlikely(size < 8))
+ return false;
int position = 0;
if (find_jpeg_marker(&position, header, size) != 0xd8 || position > size-2)
@@ -51,7 +53,7 @@ static bool IsMxpeg(stream_t *s)
if (find_jpeg_marker(&position, header, position + 2) != 0xe0)
return false;
- if (position + 2 > size)
+ if (position > size - 2)
return false;
/* Skip this jpeg header */
@@ -59,34 +61,32 @@ static bool IsMxpeg(stream_t *s)
position += header_size;
/* Get enough data to analyse the next header */
- if (position + 6 > size)
+ if (position + 8 > size)
{
- size = position + 6;
+ size = position + 8;
if( vlc_stream_Peek (s, &header, size) < size )
return false;
}
if ( !(header[position] == 0xFF && header[position+1] == 0xFE) )
return false;
- position += 2;
- header_size = GetWBE (&header[position]);
+
+ header_size = GetWBE (&header[position+2]);
/* Check if this is a MXF header. We may have a jpeg comment first */
- if (!memcmp (&header[position+2], "MXF\0", 4) )
+ if (!memcmp (&header[position+4], "MXF\0", 4) )
return true;
/* Skip the jpeg comment and find the MXF header after that */
- size = position + header_size + 8; //8 = FF FE 00 00 M X F 00
+ size = position + 2 + header_size + 8; //8 = FF FE 00 00 M X F 00
if (vlc_stream_Peek(s, &header, size ) < size)
return false;
- position += header_size;
+ position += 2 + header_size;
if ( !(header[position] == 0xFF && header[position+1] == 0xFE) )
return false;
- position += 4;
-
- if (memcmp (&header[position], "MXF\0", 4) )
+ if (memcmp (&header[position + 4], "MXF\0", 4) )
return false;
return true;
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/682660f248068aab15062a9ebc8feeb9f5816e64...055db45c63a9ddcbc2605795aafb323dbd343fb0
--
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/682660f248068aab15062a9ebc8feeb9f5816e64...055db45c63a9ddcbc2605795aafb323dbd343fb0
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help
More information about the vlc-commits
mailing list