You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Deepin Integration]~[v25-Release] fix(cve): CVE-2026-75143 - avformat/librist: honor the caller buffer size in librist_read by deepin-ci-robot@deepin-community/ffmpeg by deepin-community-ci-bot[bot] #14047
fix(ffv1): backport avcodec/rangecoder: eliminate main branch from
renorm_encoder() The x86_64 FATE run fails for fate-vsynth1/2/3-ffv1-2pass,
ffv1-v3-yuv422p10, ffv1-v3-yuv444p16 and ffv1-v3-rgb48 because
--toolchain=hardened adds -fstack-protector-all, which makes gcc -O3
miscompile the branchy form of renorm_encoder() that the 6.1 branch still
carries; the FFV1 range coder then emits a corrupt extradata (190 -> 298
bytes) which the decoder rejects with "quant_table_index out of range".
The upstream rewrite is a pure refactoring (identical bitstream) and
restores the reference hashes on all architectures. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b2da4c33e31f85b9c755f2c
db08f5db694e90ca9
CVE-2026-66040: not-affected
The overrun that upstream commit b506fafec9 hardens lives in the eXIf
chunk writer of libavcodec/pngenc.c, which sizes the chunk from
ff_exif_get_buffer()/AV_EXIF_TIFF_HEADER. Neither the helper nor
AV_FRAME_DATA_EXIF exists in 6.1.5 - pngenc.c here never writes an eXIf
chunk, EXIF output support was added after the 6.1 branch - so the
vulnerable code is absent and no patch is required.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc.patch
Package information | 软件包信息
Package repository address | 软件包仓库地址
Changelog | 更新信息
ffmpeg (7:6.1.5-0deepin9) unstable; urgency=medium
caller buffer size in librist_read Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a2
5ab3db142ce390602.patch
decoded tail to avoid heap disclosure Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825
b87d609963e862c8c.patch
AC3 trim underflow the packet size Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c
82e56995a1ef40df7
output wider than the plane Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c03
1409058571c94f6a9.patch
negative fragment index Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30e
cc58f5935d4f151e0
frame before reallocating on size change Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d
0b5ff45685766200c
counts that overflow the system header Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b84826519285
74de33772aeee7be1,https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b274f
0d21ba684446fd59b49e00f3f8e9ed954df
temp row buffer for the widest plane Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371
bbf04b39907d7a527
signed overflow in the capacity check Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae683
22720d10188fc6e30.patch
arrays that overflow the 16-bit count Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1
ea8d7f355ed780781.patch
units larger than the RTP payload buffer Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9
b451e01c376398818.patch
objects smaller than their header Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f06922
20cc772b116abc632
streams and bound the stream count Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433
f4306582aa37c3951.patch
output shorter than the strip Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca
632dd16481d8de39f
uninitilized data when the input is too short Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b
1e92665d7874d4fd7
given to can_seek_to_key_sample() Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cb8a5ca8ab36884064ac4de
5175ae82c93edfcb2.patch
renorm_encoder() The x86_64 FATE run fails for fate-vsynth1/2/3-ffv1-2pass,
ffv1-v3-yuv422p10, ffv1-v3-yuv444p16 and ffv1-v3-rgb48 because
--toolchain=hardened adds -fstack-protector-all, which makes gcc -O3
miscompile the branchy form of renorm_encoder() that the 6.1 branch still
carries; the FFV1 range coder then emits a corrupt extradata (190 -> 298
bytes) which the decoder rejects with "quant_table_index out of range".
The upstream rewrite is a pure refactoring (identical bitstream) and
restores the reference hashes on all architectures. Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b2da4c33e31f85b9c755f2c
db08f5db694e90ca9
The overrun that upstream commit b506fafec9 hardens lives in the eXIf
chunk writer of libavcodec/pngenc.c, which sizes the chunk from
ff_exif_get_buffer()/AV_EXIF_TIFF_HEADER. Neither the helper nor
AV_FRAME_DATA_EXIF exists in 6.1.5 - pngenc.c here never writes an eXIf
chunk, EXIF output support was added after the 6.1 branch - so the
vulnerable code is absent and no patch is required.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc.patch
unneeded variables Upstream:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a2905
9cb22ca3f2d59201c