Skip to content

aac: prevent crash on malformed AU headers - #2513

Open
tac2sc wants to merge 2 commits into
AlexxIT:masterfrom
tac2sc:fix/aac-malformed-au-headers
Open

tac2sc wants to merge 2 commits into
AlexxIT:masterfrom
tac2sc:fix/aac-malformed-au-headers

Conversation

@tac2sc

@tac2sc tac2sc commented Sep 21, 2026

Copy link
Copy Markdown

Summary

RTPToADTS trusted MPEG4-GENERIC AU-header lengths before slicing the RTP payload. A malformed or truncated AAC RTP packet could therefore cause an out-of-bounds slice panic and terminate the entire go2rtc process.

This change validates:

  • the minimum RTP payload size;
  • AU-header length and alignment;
  • each declared AU size against the remaining payload.

Invalid packets are dropped instead of being forwarded or crashing go2rtc.

Also updates two stale AAC test expectations to use the current uint8 channel-count type.

Testing

go test ./pkg/aac

Related

Similar malformed-AAC handling was previously addressed in the RTP depacketizer path in #697; this covers the remaining RTPToADTS path.

@tac2sc tac2sc changed the title Fix/aac malformed au headers Fix: AAC malformed au headers Sep 21, 2026
@tac2sc tac2sc changed the title Fix: AAC malformed au headers Fix: malformed aac au headers crashing go2rtc Sep 21, 2026
@tac2sc tac2sc changed the title Fix: malformed aac au headers crashing go2rtc aac: prevent crash on malformed AU headers Sep 21, 2026
@AlexxIT AlexxIT self-assigned this Oct 1, 2026
@AlexxIT AlexxIT added enhancement New feature or request size/small labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request size/small

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants