Bug#1142962: trixie-pu: package bcg729/1.1.1-3+deb13u1

Guillem Jover <[email protected]> Tue, 28 Jul 2026 21:32:01 +0200
Newsgroups gmane.linux.debian.devel.release
Message-ID <amkDsaPfPlL8OxPh__45076.013174706$1785267212$gmane$org@thunder.hadrons.org>
--jJJWA/Yptg5IgqxP
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:bcg729
User: [email protected]
Usertags: pu

Hi!

[ Reason ]

This update includes a SIGFPE fix due to a division by zero. This was
found to affect rtpengine when processing SIP packets from external
sources, which can cause crashes and DoS scenarios for example on VoIP
services.

[ Impact ]

Crashes/DoS, loss of VoIP service.

[ Tests ]

Richard Fuchs (CCed) tested this when filing this upstream [U], and now
again with the packages I've built. He prepared the attached test program
and the following test session, which shows the SIGFPE with the unfixed
packages, and how the SIGFPE no longer applies once fixed.

  [U] https://github.com/BelledonneCommunications/bcg729/issues/21

  ,---
  # dpkg -l libbcg729\*
  Desired=Unknown/Install/Remove/Purge/Hold
  | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
  |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
  ||/ Name                     Version      Architecture Description
  +++-========================-============-============-==========================================================
  ii  libbcg729-0:amd64        1.1.1-3      amd64        ITU G.729 Annex A compatible audio codec
  ii  libbcg729-0-dbgsym:amd64 1.1.1-3      amd64        debug symbols for libbcg729-0
  ii  libbcg729-dev:amd64      1.1.1-3      amd64        Development files for the ITU G.729 compatible audio codec
  # gcc test.c -o test -lbcg729
  # ./test
  Floating point exception (core dumped)
  # 136 # ls -la *deb
  -rw-r--r-- 1 root root 35600 Jul 28 21:10 libbcg729-0_1.1.1-3+deb13u1_amd64.deb
  -rw-r--r-- 1 root root 70472 Jul 28 21:10 libbcg729-0-dbgsym_1.1.1-3+deb13u1_amd64.deb
  -rw-r--r-- 1 root root  8320 Jul 28 21:10 libbcg729-dev_1.1.1-3+deb13u1_amd64.deb
  # dpkg -i *.deb
  (Reading database ... 174488 files and directories currently installed.)
  Preparing to unpack libbcg729-0_1.1.1-3+deb13u1_amd64.deb ...
  Unpacking libbcg729-0:amd64 (1.1.1-3+deb13u1) over (1.1.1-3) ...
  Preparing to unpack libbcg729-0-dbgsym_1.1.1-3+deb13u1_amd64.deb ...
  Unpacking libbcg729-0-dbgsym:amd64 (1.1.1-3+deb13u1) over (1.1.1-3) ...
  Preparing to unpack libbcg729-dev_1.1.1-3+deb13u1_amd64.deb ...
  Unpacking libbcg729-dev:amd64 (1.1.1-3+deb13u1) over (1.1.1-3) ...
  Setting up libbcg729-0:amd64 (1.1.1-3+deb13u1) ...
  Setting up libbcg729-0-dbgsym:amd64 (1.1.1-3+deb13u1) ...
  Setting up libbcg729-dev:amd64 (1.1.1-3+deb13u1) ...
  Processing triggers for libc-bin (2.41-12+deb13u3) ...
  # dpkg -l libbcg729\*
  Desired=Unknown/Install/Remove/Purge/Hold
  | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
  |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
  ||/ Name                     Version         Architecture Description
  +++-========================-===============-============-==========================================================
  ii  libbcg729-0:amd64        1.1.1-3+deb13u1 amd64        ITU G.729 Annex A compatible audio codec
  ii  libbcg729-0-dbgsym:amd64 1.1.1-3+deb13u1 amd64        debug symbols for libbcg729-0
  ii  libbcg729-dev:amd64      1.1.1-3+deb13u1 amd64        Development files for the ITU G.729 compatible audio codec
  # ./test
  `---

[ Risks ]

This has been present in Debian unstable and testing for a while now. It
seems like the targeted fix has low risk.

[ Checklist ]

  [√] *all* changes are documented in the d/changelog
  [√] I reviewed all changes and I approve them
  [√] attach debdiff against the package in (old)stable
  [√] the issue is verified as fixed in unstable

[ Changes ]

The fix checks for one of the values to avoid a division by zero, that
then would otherwise cause a SIGFPE.

Thanks,
Guillem

--jJJWA/Yptg5IgqxP
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment; filename=bcg729_trixie.debdiff

diff -Nru bcg729-1.1.1/debian/changelog bcg729-1.1.1/debian/changelog
--- bcg729-1.1.1/debian/changelog	2025-02-07 08:42:06.000000000 +0100
+++ bcg729-1.1.1/debian/changelog	2026-07-28 18:26:01.000000000 +0200
@@ -1,3 +1,10 @@
+bcg729 (1.1.1-3+deb13u1) trixie; urgency=medium
+
+  * Fix SIGFPE due to a division by zero in bcg729Encoder().
+    Patch taken from upstream.
+
+ -- Guillem Jover <[email protected]>  Tue, 28 Jul 2026 18:26:01 +0200
+
 bcg729 (1.1.1-3) unstable; urgency=medium
 
   * cmake patches from upstream
diff -Nru bcg729-1.1.1/debian/patches/0006-Avoid-possible-division-by-0.patch bcg729-1.1.1/debian/patches/0006-Avoid-possible-division-by-0.patch
--- bcg729-1.1.1/debian/patches/0006-Avoid-possible-division-by-0.patch	1970-01-01 01:00:00.000000000 +0100
+++ bcg729-1.1.1/debian/patches/0006-Avoid-possible-division-by-0.patch	2026-07-28 18:23:41.000000000 +0200
@@ -0,0 +1,29 @@
+From 53d06732711b8b03d292a4218c9570ec464cb751 Mon Sep 17 00:00:00 2001
+From: johan pascal <[email protected]>
+Date: Mon, 6 Jul 2026 22:49:06 +0200
+Subject: [PATCH] Avoid possible division by 0 thanks Richard Fuchs
+
+---
+ src/LP2LSPConversion.c | 6 +++++-
+ 1 file changed, 5 insertions(+), 1 deletion(-)
+
+diff --git a/src/LP2LSPConversion.c b/src/LP2LSPConversion.c
+index 2bbae5d..40d57bc 100644
+--- a/src/LP2LSPConversion.c
++++ b/src/LP2LSPConversion.c
+@@ -100,7 +100,11 @@ int LP2LSPConversion(word16_t LPCoefficients[], word16_t LSPCoefficients[])
+ 
+ 			/* linear interpolation for better root accuracy */
+ 			/* xMean = xLow - (xHigh-xLow)* previousCx/(Cx-previousCx); */
+-			xMean = (word16_t)SUB32(xLow, MULT16_32_Q15(SUB32(xHigh, xLow), DIV32(SSHL(SATURATE(previousCx, MAXINT17), 14), SHR(SUB32(Cx, previousCx), 1)))); /* Cx are in Q2.15 so we can shift them left 14 bits, the denominator is shifted righ by 1 so the division result is in Q15 */
++			if (previousCx == Cx) { // avoid possible division by 0: consider previousCx/(Cx-previousCx) to be MAXINT32 or MININT32 depending on previousCx sign
++				xMean = (word16_t)SUB32(xLow, MULT16_32_Q15(SUB32(xHigh, xLow), previousCx>0?MAXINT32:MININT32));
++			} else {
++				xMean = (word16_t)SUB32(xLow, MULT16_32_Q15(SUB32(xHigh, xLow), SSHL(DIV32(SSHL(SATURATE(previousCx, MAXINT17), 14), SUB32(Cx, previousCx)), 1))); /* Cx are in Q2.15 so we can shift them left 14 bits, the division result is in Q14 so we shift left it one to put it back to Q15 */
++			}
+ 
+ 			/* recompute previousCx with the new coefficients */
+ 			previousCx = ChebyshevPolynomial(xMean, polynomialCoefficients);
+-- 
+2.53.0
+
diff -Nru bcg729-1.1.1/debian/patches/series bcg729-1.1.1/debian/patches/series
--- bcg729-1.1.1/debian/patches/series	2025-02-07 08:42:06.000000000 +0100
+++ bcg729-1.1.1/debian/patches/series	2026-07-28 18:25:25.000000000 +0200
@@ -3,3 +3,4 @@
 0003-No-longer-use-CMAKE_BUILD_TYPE-to-allow-configuratio.patch
 0004-cmake-files-installed-under-usr-lib-arch-triplet.patch
 0005-Prevent-RPM-.spec-file-generation-which-breaks-repea.patch
+0006-Avoid-possible-division-by-0.patch

--jJJWA/Yptg5IgqxP
Content-Type: text/x-csrc; charset=us-ascii
Content-Disposition: attachment; filename=bcg729_sigfpe-test.c

#include <bcg729/encoder.h>

int main(void) {
	const int16_t frame1[80] = { 679, -1351, -1996, -578, 1248,
		1560, -153, -1834, -1585, 240, 1658, 1014, -953, -1999,
		-932, 1053, 1688, 289, -1579, -1906, -220, 1466, 1268,
		-668, -2128, -1495, 523, 1556, 512, -1519, -2100, -747,
		1143, 1392, -289, -2004, -1753, 103, 1554, 908, -1122,
		-2168, -1134, 756, 1454, 58, -1814, -2076, -429, 1298,
		1035, -868, -2234, -1599, 385, 1451, 375, -1625, -2270,
		-884, 973, 1225, -459, -2173, -1923, -65, 1323, 674,
		-1355, -2400, -1366, 650, 1285, -145, -1983, -2244,
		-559, 1127, 930, -949 };
	const int16_t frame2[80] = { -2339, -1705, 282, 1380, 237,
		-1730, -2439, -1022, 805, 1056, -651, -2341, -2156,
		-306, 1089, 442, -1556, -2665, -1567, 418, 1052, -313,
		-2151, -2413, -721, 959, 698, -1118, -2508, -1872, 81,
		1210, 69, -1899, -2544, -1189, 637, 887, -796, -2510,
		-2260, -433, 985, 339, -1659, -2736, -1704, 315, 949,
		-481, -2320, -2582, -920, 792, 594, -1340, -2740,
		-2106, -118, 947, -132, -2130, -2774, -1388, 469, 719,
		-963, -2676, -2426, -600, 818, 172, -1827, -2904,
		-1838, 148, 781, -618, -2488, -2748 };
	const int16_t frame3[80] = { -1055, 624, 363, -1477, -2905,
		-2271, -287, 780, -298, -2296, -2942, -1589, 302, 552,
		-1162, -2844, -2594, -769, 650, 4, -1993, -3072, -2006,
		-20, 613, -752, -2654, -2917, -1215, 454, 194, -1644,
		-3073, -2440, -453, 613, -467, -2464, -3111, -1756,
		134, 384, -1322, -3012, -2762, -936, 482, -165, -2161,
		-3240, -2174, -188, 446, -950, -2821, -3083, -1406,
		289, 25, -1810, -3241, -2608, -623, 443, -633, -2632,
		-3279, -1891, -35, 218, -1473, -3180, -2930, -1103,
		314, -331, -2329, -3408, -2340, -356 };

	bcg729EncoderChannelContextStruct *e = initBcg729EncoderChannel(0);

	uint8_t o[10];
	uint8_t l;

	bcg729Encoder(e, frame1, o, &l);
	bcg729Encoder(e, frame2, o, &l);
	bcg729Encoder(e, frame3, o, &l);

	closeBcg729EncoderChannel(e);

	return 0;
}

--jJJWA/Yptg5IgqxP--