From d7997a46935e18eb18764301fc4006d407ee9738 Mon Sep 17 00:00:00 2001 From: Funda Wang Date: Sun, 23 Mar 2025 22:38:15 +0800 Subject: [PATCH] fix CVE-2025-22991 --- backport-CVE-2025-22921.patch | 29 +++++++++++++++++++++++++++++ ffmpeg.spec | 6 +++++- 2 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 backport-CVE-2025-22921.patch diff --git a/backport-CVE-2025-22921.patch b/backport-CVE-2025-22921.patch new file mode 100644 index 0000000..3a522c8 --- /dev/null +++ b/backport-CVE-2025-22921.patch @@ -0,0 +1,29 @@ +From 7f9c7f9849a2155224711f0ff57ecdac6e4bfb57 Mon Sep 17 00:00:00 2001 +From: James Almer +Date: Wed, 1 Jan 2025 23:58:39 -0300 +Subject: [PATCH] avcodec/jpeg2000dec: clear array length when freeing it + +Fixes NULL pointer dereferences. +Fixes ticket #11393. + +Reviewed-by: Michael Niedermayer +Signed-off-by: James Almer +--- + libavcodec/jpeg2000dec.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/libavcodec/jpeg2000dec.c b/libavcodec/jpeg2000dec.c +index e5e897a29f..b82d85d5ee 100644 +--- a/libavcodec/jpeg2000dec.c ++++ b/libavcodec/jpeg2000dec.c +@@ -1521,6 +1521,7 @@ static int jpeg2000_decode_packet(Jpeg2000DecoderContext *s, Jpeg2000Tile *tile, + } + } + av_freep(&cblk->lengthinc); ++ cblk->nb_lengthinc = 0; + } + } + // Save state of stream +-- +2.48.1 + diff --git a/ffmpeg.spec b/ffmpeg.spec index 097bb9b..83ac904 100644 --- a/ffmpeg.spec +++ b/ffmpeg.spec @@ -62,7 +62,7 @@ Summary: Digital VCR and streaming server Name: ffmpeg%{?flavor} Version: 6.1.1 -Release: 19 +Release: 20 License: GPL-3.0-or-later URL: http://ffmpeg.org/ Source0: http://ffmpeg.org/releases/ffmpeg-%{version}.tar.xz @@ -86,6 +86,7 @@ Patch15: backport-CVE-2024-36618.patch Patch16: backport-CVE-2024-36617.patch Patch17: backport-CVE-2024-36619.patch Patch18: backport-CVE-2024-35369.patch +Patch19: backport-CVE-2025-22921.patch Requires: %{name}-libs%{?_isa} = %{version}-%{release} %{?_with_cuda:BuildRequires: cuda-minimal-build-%{_cuda_version_rpm} cuda-drivers-devel} @@ -418,6 +419,9 @@ install -pm755 tools/qt-faststart %{buildroot}%{_bindir} %changelog +* Sun Mar 23 2025 Funda Wang - 6.1.1-20 +- fix CVE-2025-22991 + * Wed Jan 08 2025 dingjiachun - 6.1.1-19 - Add compilation options to support sw_64 architecture -- Gitee