[FFmpeg-devel,PR] avcodec/ratecontrol: count the pass-2 log entries without reading past an empty log (PR #24759)

Message ID 20260928222201.101242E59D@ffbox0-bg.ffmpeg.org
State New
Headers
Series [FFmpeg-devel,PR] avcodec/ratecontrol: count the pass-2 log entries without reading past an empty log (PR #24759) |

Commit Message

Sean McGovern Sept. 28, 2026, 10:22 p.m. UTC
PR #24759 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24759
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24759.patch

Fixes: heap-buffer-overflow
Fixes: lAyRPnaxSAiw
Found during triage/review of the security report d8mJHYOGopsd



>From c154a5654a5fe164a7b99835da9b933722c17b62 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <michael@niedermayer.cc>
Date: Fri, 25 Sep 2026 05:42:17 +0200
Subject: [PATCH] avcodec/ratecontrol: count the pass-2 log entries without
 reading past an empty log

Fixes: heap-buffer-overflow
Fixes: lAyRPnaxSAiw
Found during triage/review of the security report d8mJHYOGopsd
---
 libavcodec/ratecontrol.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)
  

Patch

diff --git a/libavcodec/ratecontrol.c b/libavcodec/ratecontrol.c
index ab2c43b8d2..4d2d2cdd10 100644
--- a/libavcodec/ratecontrol.c
+++ b/libavcodec/ratecontrol.c
@@ -571,9 +571,8 @@  av_cold int ff_rate_control_init(MPVMainEncContext *const m)
         char *p;
 
         /* find number of pics */
-        p = avctx->stats_in;
-        for (i = -1; p; i++)
-            p = strchr(p + 1, ';');
+        for (i = 0, p = avctx->stats_in; p && (p = strchr(p, ';')); i++)
+            p++;
         i += m->max_b_frames;
         if (i <= 0 || i >= INT_MAX / sizeof(RateControlEntry))
             return -1;