[PR] avformat/ty: don't let the Series2 AC3 trim underflow the packet size (PR #23767)

michaelni via ffmpeg-devel <[email protected]> Sat, 11 Jul 2026 02:13:24 -0000
Newsgroups gmane.comp.video.ffmpeg.devel
Message-ID <178373600573.59.15913105807103436355@29965ddac10e>
PR #23767 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767.patch

Fixes: negative-size-param
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)



>From 2f7a688e67075d55943db20419d513a91ed268ce Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <[email protected]>
Date: Fri, 10 Jul 2026 04:07:35 +0200
Subject: [PATCH] avformat/ty: don't let the Series2 AC3 trim underflow the
 packet size

Fixes: negative-size-param
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)
---
 libavformat/ty.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/ty.c b/libavformat/ty.c
index 9be027fcca..842d97038c 100644
--- a/libavformat/ty.c
+++ b/libavformat/ty.c
@@ -578,7 +578,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt)
         if (ty->audio_type == TIVO_AUDIO_AC3 &&
                 ty->tivo_series == TIVO_SERIES2) {
             if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) {
-                pkt->size -= 2;
+                pkt->size -= FFMIN(pkt->size, 2);
                 ty->ac3_pkt_size = 0;
             } else {
                 ty->ac3_pkt_size += pkt->size;
-- 
2.52.0

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]