Skip to content

fix(cve): CVE-2026-66040 - avcodec/pngenc: fix overrun caused by exif size discrepancy - #44

Closed
deepin-ci-robot wants to merge 12 commits into
masterfrom
fix-cve/CVE-2026-66040
Closed

deepin-ci-robot wants to merge 12 commits into
masterfrom
fix-cve/CVE-2026-66040

Conversation

@deepin-ci-robot

@deepin-ci-robot deepin-ci-robot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

CVE: CVE-2026-66040 (high) - fix overrun caused by exif size discrepancy
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-75142 (high) - mpegenc: reject stream counts that overflow the system header
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1,https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b274f0d21ba684446fd59b49e00f3f8e9ed954df

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-66039 (high) - 堆缓冲区溢出
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-66036 - 兼容性适配修改:为 HQDN3DContext 结构体添加 format/width/height 字段并初始化,解决 heap out-of-bounds write 漏洞修复引入的编译错误

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-65706 (high) - avfilter/vf_swaprect: size the temp row buffer for the widest plane - out of array access
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-70628 (high) - dvbsub_parser 中容量检查的有符号整数溢出漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-75141 (high) - 整数溢出导致数组越界访问
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-75144 (high) - rtpenc_vc2hq: reject data units larger than the RTP payload buffer
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-64834 (high) - FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-64830 (high) - 堆缓冲区溢出漏洞在 vobsub 字幕处理中
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-64835 (high) - avcodec/adx: sync decoder channel state on NEW_EXTRADATA
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-64833 (high) - out of array read in DTS-HD SPDIF encoder
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-70631 (medium) - avcodec/tiff: reject inflate output shorter than the strip - use of uninitialized memory
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-70629 - 兼容性适配修改:无额外兼容性问题,直接应用 CVE 修复补丁

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b

… size discrepancy

CVE: CVE-2026-66040 (high) - fix overrun caused by exif size discrepancy
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign zeno-sole for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

/hold
因为该quilt包的上游版本号变更,详情见: deepin-community/infra-settings#134

@github-actions

Copy link
Copy Markdown

TAG Bot

TAG: 7%6.1.5-0deepin9
EXISTED: no
DISTRIBUTION: unstable

deepin-ci-robot and others added 11 commits September 21, 2026 02:12
…t overflow the system header

CVE: CVE-2026-75142 (high) - mpegenc: reject stream counts that overflow the system header
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1,https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b274f0d21ba684446fd59b49e00f3f8e9ed954df

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ffer for the widest plane

CVE: CVE-2026-65706 (high) - avfilter/vf_swaprect: size the temp row buffer for the widest plane - out of array access
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ow in the capacity check

CVE: CVE-2026-70628 (high) - dvbsub_parser 中容量检查的有符号整数溢出漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
… overflow the 16-bit count

CVE: CVE-2026-75141 (high) - 整数溢出导致数组越界访问
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…arger than the RTP payload buf

CVE: CVE-2026-75144 (high) - rtpenc_vc2hq: reject data units larger than the RTP payload buffer
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…aller than their header

CVE: CVE-2026-64834 (high) - FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…d bound the stream count

CVE: CVE-2026-64830 (high) - 堆缓冲区溢出漏洞在 vobsub 字幕处理中
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…r than the strip

CVE: CVE-2026-70631 (medium) - avcodec/tiff: reject inflate output shorter than the strip - use of uninitialized memory
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ta when the input is too short

CVE: CVE-2026-70629 (medium) - 修复 rscc 解码器中的堆溢出写入漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-70629 - 兼容性适配修改:无额外兼容性问题,直接应用 CVE 修复补丁

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…can_seek_to_key_sample()

CVE: CVE-2026-13858 (medium) - Fix negative index given to can_seek_to_key_sample()
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cb8a5ca8ab36884064ac4de5175ae82c93edfcb2.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@hudeng-go

Copy link
Copy Markdown
Contributor

Content merged into #43 (branch fix-cve/CVE-2026-75143).

All applicable commits of this PR were cherry-picked onto #43 so that both CVE
sets ship in one update:

CVE-2026-66040 is not applied. The overrun that upstream b506fafec9
hardens lives in the eXIf chunk writer of libavcodec/pngenc.c, which sizes
the chunk from ff_exif_get_buffer() / AV_EXIF_TIFF_HEADER. Neither the
helper nor AV_FRAME_DATA_EXIF exists in FFmpeg 6.1.5 — pngenc.c in this
package never writes an eXIf chunk (EXIF output support was added after the
6.1 branch) — so the generated patch referenced APIs that do not exist and
broke the build with:

src/libavcodec/pngenc.c:617:18: error: implicit declaration of function 'ff_exif_get_buffer' [-Werror=implicit-function-declaration]
src/libavcodec/pngenc.c:617:42: error: 'AV_EXIF_TIFF_HEADER' undeclared

The vulnerable code is absent, so the CVE is recorded as not-affected in
debian/changelog instead of being patched (same handling as the earlier
CVE-2024-32228 entry).

The merged branch was verified locally: all 27 patches apply cleanly, the
build is clean and the full FATE suite passes.

Closing in favour of #43.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants