Projects
SLE15
faad2
Sign Up
Log In
Username
Password
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
Expand all
Collapse all
Changes of Revision 5
View file
_service
Changed
@@ -1,7 +1,7 @@ <services> <service name="obs_scm"> <param name="filename">faad2</param> - <param name="revision">f2f4e8e8093df276fb1f6f96eb69efd37aba3da3</param> + <param name="revision">6918ebb51b8f7e86278da15884bd7114e4b9661e</param> <param name="scm">git</param> <param name="submodules">disable</param> <param name="url">https://github.com/knik0/faad2.git</param>
View file
_service:obs_scm:faad2-2.11.2.obscpio/.github/workflows/build.yaml -> _service:obs_scm:faad2-2.11.3.obscpio/.github/workflows/build.yaml
Changed
@@ -59,7 +59,7 @@ - name: MSVC os: windows-latest cmake_args: >- - -G "Visual Studio 17 2022" -A x64 + -G "Visual Studio 18 2026" -A x64 cmake_build_options: >- --config Release - name: OSX
View file
_service:obs_scm:faad2-2.11.2.obscpio/ChangeLog -> _service:obs_scm:faad2-2.11.3.obscpio/ChangeLog
Changed
@@ -1,3 +1,39 @@ +2.11.3 (2026-08-19): + Dario Binacchi + * Fix ISO C warning in `libfaad/fixed.h` + + Fabian Greffrath + * Check for `mp4config.frame.nsclices == 0` in `frontend/mp4read.c` to fix + Heap Buffer Overflow + + Kevin Valerio + * SBR: prevent heap overflow in channel-pair reconstruction + + netliomax25-code + * Fix off-by-one frame index check in `mp4read_seek` + * Fix integer overflow in `stszin`/`stscin` allocation size checks + * Bound `sscanf` field width in option parsing + * Fix out-of-bounds `iq_table` read in `iquant` for -32768 + * Prevent `length_of_rvlc_sf` underflow in `rvlc_scale_factor_data` + * Fix out-of-bounds `Xsbr` write in `hf_assembly` sinusoid addition + * Fix out-of-bounds `X` underflow in SBR low-power QMF assembly + * Fix `ssr_gc_function` signature mismatch in `ssr_gain_control` + * Fix signed overflow in `estimate_current_envelope` energy sum + * Cap escape length in `huffman_spectral_data_2` + * Prevent `num_bits_left` underflow in `ps_data` extension parsing + * Fix signed overflow in fixed-point sample rounding before saturation + + Steve Lhomme + * Add sanity checks on the width in `libfaad/specrec.c` + * Check the last `swb_offset` value is valid in `libfaad/specrec.c` + * Return early from `NeAACDecInit` when the object type can't be supported + + Thomas Lange + * Fix null pointer dereferences in intra channel and long term prediction + + hexapod0815 + * Increase the ASC buffer from 10 to 64 bytes in `frontend/mp4read.h` + 2.11.2 (2025-03-04): Armin Novak * Add option BUILD_FAAD_CLI
View file
_service:obs_scm:faad2-2.11.2.obscpio/frontend/main.c -> _service:obs_scm:faad2-2.11.3.obscpio/frontend/main.c
Changed
@@ -1114,7 +1114,7 @@ if (optarg) { char dr10; - if (sscanf(optarg, "%s", dr) < 1) { + if (sscanf(optarg, "%9s", dr) < 1) { def_srate = 0; } else { def_srate = atoi(dr); @@ -1125,7 +1125,7 @@ if (optarg) { char dr10; - if (sscanf(optarg, "%s", dr) < 1) + if (sscanf(optarg, "%9s", dr) < 1) { format = 1; } else { @@ -1139,7 +1139,7 @@ if (optarg) { char dr10; - if (sscanf(optarg, "%s", dr) < 1) + if (sscanf(optarg, "%9s", dr) < 1) { outputFormat = FAAD_FMT_16BIT; /* just use default */ } else { @@ -1156,7 +1156,7 @@ if (optarg) { char dr10; - if (sscanf(optarg, "%s", dr) < 1) + if (sscanf(optarg, "%9s", dr) < 1) { object_type = LC; /* default */ } else {
View file
_service:obs_scm:faad2-2.11.2.obscpio/frontend/mp4read.c -> _service:obs_scm:faad2-2.11.3.obscpio/frontend/mp4read.c
Changed
@@ -350,9 +350,9 @@ if (!mp4config.frame.nsclices) return ERR_FAIL; - tmp = sizeof(slice_info_t) * mp4config.frame.nsclices; - if (tmp < mp4config.frame.nsclices) + if (mp4config.frame.nsclices > UINT32_MAX / sizeof(slice_info_t)) return ERR_FAIL; + tmp = sizeof(slice_info_t) * mp4config.frame.nsclices; mp4config.frame.map = malloc(tmp); if (!mp4config.frame.map) return ERR_FAIL; @@ -396,9 +396,9 @@ if (!mp4config.frame.nsamples) return ERR_FAIL; - tmp = sizeof(frame_info_t) * mp4config.frame.nsamples; - if (tmp < mp4config.frame.nsamples) + if (mp4config.frame.nsamples > UINT32_MAX / sizeof(frame_info_t)) return ERR_FAIL; + tmp = sizeof(frame_info_t) * mp4config.frame.nsamples; mp4config.frame.info = malloc(tmp); if (!mp4config.frame.info) return ERR_FAIL; @@ -1016,7 +1016,7 @@ int mp4read_seek(uint32_t framenum) { - if (framenum > mp4config.frame.nsamples) + if (framenum >= mp4config.frame.nsamples) return ERR_FAIL; if (fseek(g_fin, mp4config.frame.infoframenum.offset, SEEK_SET)) return ERR_FAIL;
View file
_service:obs_scm:faad2-2.11.2.obscpio/frontend/mp4read.h -> _service:obs_scm:faad2-2.11.3.obscpio/frontend/mp4read.h
Changed
@@ -57,7 +57,11 @@ // AudioSpecificConfig data: struct { - uint8_t buf10; + // Some muxers (e.g. FFmpeg/libavformat) zero-pad the DecSpecificInfo + // descriptor, so the declared ASC length can exceed the ~2 bytes of + // meaningful data. A 10-byte buffer rejected such files in esdsin() + // with "parse:-1"; 64 bytes safely holds any real AudioSpecificConfig. + uint8_t buf64; uint32_t size; } asc; struct {
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/decoder.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/decoder.c
Changed
@@ -372,6 +372,9 @@ } #endif + if (can_decode_ot(hDecoder->object_type) < 0) + return -1; + /* must be done before frameLength is divided by 2 for LD */ #ifdef SSR_DEC if (hDecoder->object_type == SSR) @@ -385,9 +388,6 @@ hDecoder->frameLength >>= 1; #endif - if (can_decode_ot(hDecoder->object_type) < 0) - return -1; - return bits; }
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/error.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/error.c
Changed
@@ -65,6 +65,6 @@ "No standard extension payload allowed in DRM", "PCE shall be the first element in a frame", "Bitstream value not allowed by specification", - "MAIN prediction not initialised" + "MAIN prediction not initialised", + "Long term prediction not initialised" }; -
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/error.h -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/error.h
Changed
@@ -35,7 +35,7 @@ extern "C" { #endif -#define NUM_ERROR_MESSAGES 34 +#define NUM_ERROR_MESSAGES 35 extern char *err_msg; #ifdef __cplusplus
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/huffman.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/huffman.c
Changed
@@ -561,7 +561,7 @@ neg = (spk < 0) ? 1 : 0; - for (i = 4; ; i++) + for (i = 4; i < 16; i++) { uint8_t b; if (get1bit_hcr(ld, &b)) @@ -570,7 +570,7 @@ break; } - if (i > 32) + if (i >= 16) return -1; if (getbits_hcr(ld, i, &off))
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/lt_predict.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/lt_predict.c
Changed
@@ -137,11 +137,13 @@ { if (sig_in >= 0) { - sig_in += (1 << (REAL_BITS-1)); + if (sig_in <= 0x7FFFFFFF - (1 << (REAL_BITS-1))) + sig_in += (1 << (REAL_BITS-1)); if (sig_in >= REAL_CONST(32768)) return 32767; } else { - sig_in += -(1 << (REAL_BITS-1)); + if (sig_in >= (int32_t)0x80000000 + (1 << (REAL_BITS-1))) + sig_in += -(1 << (REAL_BITS-1)); if (sig_in <= REAL_CONST(-32768)) return -32768; }
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/output.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/output.c
Changed
@@ -488,13 +488,15 @@ hDecoder->internal_channel); if (tmp >= 0) { - tmp += (1 << (REAL_BITS-1)); + if (tmp <= 0x7FFFFFFF - (1 << (REAL_BITS-1))) + tmp += (1 << (REAL_BITS-1)); if (tmp >= REAL_CONST(32767)) { tmp = REAL_CONST(32767); } } else { - tmp += -(1 << (REAL_BITS-1)); + if (tmp >= (int32_t)0x80000000 + (1 << (REAL_BITS-1))) + tmp += -(1 << (REAL_BITS-1)); if (tmp <= REAL_CONST(-32768)) { tmp = REAL_CONST(-32768); @@ -511,14 +513,16 @@ hDecoder->internal_channel); if (tmp >= 0) { - tmp += (1 << (REAL_BITS-9)); + if (tmp <= 0x7FFFFFFF - (1 << (REAL_BITS-9))) + tmp += (1 << (REAL_BITS-9)); tmp >>= (REAL_BITS-8); if (tmp >= 8388607) { tmp = 8388607; } } else { - tmp += -(1 << (REAL_BITS-9)); + if (tmp >= (int32_t)0x80000000 + (1 << (REAL_BITS-9))) + tmp += -(1 << (REAL_BITS-9)); tmp >>= (REAL_BITS-8); if (tmp <= -8388608) { @@ -538,9 +542,11 @@ hDecoder->internal_channel); if (tmp >= 0) { - tmp += half; + if (tmp <= 0x7FFFFFFF - half) + tmp += half; } else { - tmp += -half; + if (tmp >= (int32_t)0x80000000 + half) + tmp += -half; } tmp = SAT_SHIFT(tmp, exp, sat_shift_mask); int_sample_buffer(i*channels)+ch = tmp;
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/ps_syntax.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/ps_syntax.c
Changed
@@ -450,11 +450,20 @@ num_bits_left = 8 * cnt; while (num_bits_left > 7) { + uint16_t bits_read; uint8_t ps_extension_id = (uint8_t)faad_getbits(ld, 2 DEBUGVAR(1,1013,"ps_data(): ps_extension_size")); num_bits_left -= 2; - num_bits_left -= ps_extension(ps, ld, ps_extension_id, num_bits_left); + bits_read = ps_extension(ps, ld, ps_extension_id, num_bits_left); + + /* ps_extension() decodes a variable amount of Huffman data and does + not stop at the advertised ps_extension_size, so it can read more + than num_bits_left. Clamp instead of letting the uint16_t wrap. */ + if (bits_read > num_bits_left) + num_bits_left = 0; + else + num_bits_left -= bits_read; } faad_getbits(ld, num_bits_left
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/rvlc.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/rvlc.c
Changed
@@ -92,6 +92,12 @@ ics->dpcm_noise_nrg = (uint16_t)faad_getbits(ld, 9 DEBUGVAR(1,152,"rvlc_scale_factor_data(): dpcm_noise_nrg")); + /* the 9 bits of dpcm_noise_nrg are counted in length_of_rvlc_sf, so a + conformant value is at least 9; reject a smaller one before the + unsigned subtraction wraps length_of_rvlc_sf to a huge value */ + if (ics->length_of_rvlc_sf < 9) + return 8; + ics->length_of_rvlc_sf -= 9; }
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/sbr_dec.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/sbr_dec.c
Changed
@@ -444,8 +444,14 @@ { QMF_RE(Xlk) = 0; } - QMF_RE(Xlkx_band - 1 + bsco_band) += - QMF_RE(sbr->Xsbrchl + sbr->tHFAdjkx_band - 1 + bsco_band); + /* kx_band can be 0 (kx_prev on the first frame's leading slots), + which would make kx_band - 1 + bsco_band index Xl-1. There is + no band below 0 to add in that case, so skip the overlap. */ + if (kx_band + bsco_band > 0) + { + QMF_RE(Xlkx_band - 1 + bsco_band) += + QMF_RE(sbr->Xsbrchl + sbr->tHFAdjkx_band - 1 + bsco_band); + } #endif } }
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/sbr_hfadj.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/sbr_hfadj.c
Changed
@@ -138,13 +138,19 @@ qmf_t XsbrMAX_NTSRHFG64, uint8_t ch) { uint8_t m, l, j, k, k_l, k_h, p; - real_t nrg, div; + real_t div; (void)adj; /* TODO: remove parameter? */ #ifdef FIXED_POINT + /* the per-bin energy is accumulated over the envelope's time slots and, + for the wider bands, its QMF bins; that sum exceeds 32 bits on ordinary + content, so keep it in 64 bits. the running int32 sum otherwise wraps + before the limit test below can reject an over-range energy. */ + int64_t nrg; const real_t half = REAL_CONST(0.5); real_t limit; real_t mul; #else + real_t nrg; const real_t half = 0; /* Compiler is smart enough to eliminate +0 op. */ const real_t limit = FLT_MAX; #endif @@ -1713,7 +1719,7 @@ QMF_RE(Xsbri + sbr->tHFAdjm+sbr->kx) -= (rev*phi_rei_min1 * MUL_F(adj->S_M_boostlm - 1, FRAC_CONST(0.00815))); } - if (m + sbr->kx < 64) + if (m + sbr->kx + 1 < 64) { QMF_RE(Xsbri + sbr->tHFAdjm+sbr->kx + 1) += (rev*phi_rei_min1 * MUL_F(adj->S_M_boostlm, FRAC_CONST(0.00815)));
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/specrec.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/specrec.c
Changed
@@ -372,6 +372,9 @@ #ifdef LD_DEC } #endif + if (ics->num_swb > 0 && ics->swb_offsetics->num_swb < ics->swb_offsetics->num_swb-1) { + return 32; + } return 0; case EIGHT_SHORT_SEQUENCE: ics->num_windows = 8; @@ -444,34 +447,38 @@ real_t x1, x2; #endif int16_t sgn = 1; + /* compute the magnitude in int: -q is evaluated as int and so does not + wrap for q == -32768 the way an int16_t negation would, which keeps the + comparison against IQ_TABLE_SIZE in range like the floating-point path */ + int aq = q; - if (q < 0) + if (aq < 0) { - q = -q; + aq = -aq; sgn = -1; } - if (q < IQ_TABLE_SIZE) + if (aq < IQ_TABLE_SIZE) { //#define IQUANT_PRINT #ifdef IQUANT_PRINT - //printf("0x%.8X\n", sgn * tabq); - printf("%d\n", sgn * tabq); + //printf("0x%.8X\n", sgn * tabaq); + printf("%d\n", sgn * tabaq); #endif - return sgn * tabq; + return sgn * tabaq; } #ifndef BIG_IQ_TABLE - if (q >= 8192) + if (aq >= 8192) { *error = 17; return 0; } /* linear interpolation */ - x1 = tabq>>3; - x2 = tab(q>>3) + 1; - return sgn * 16 * (MUL_R(errcorrq&7,(x2-x1)) + x1); + x1 = tabaq>>3; + x2 = tab(aq>>3) + 1; + return sgn * 16 * (MUL_R(errcorraq&7,(x2-x1)) + x1); #else *error = 17; return 0; @@ -590,6 +597,13 @@ int16_t scale_factor = ics->scale_factorsgsfb; width = ics->swb_offsetsfb+1 - ics->swb_offsetsfb; + if (width + 3 >= 1024) + { + // quant_data contains 1024 uint16_t, the k iterator + 3 + // should never reach more 1024 + error = 17; + continue; + } #ifdef FIXED_POINT scale_factor -= 100; @@ -992,8 +1006,8 @@ /* MAIN object type prediction */ if (hDecoder->object_type == MAIN) { - if (!hDecoder->pred_statsce->channel) - return 33; + if (!hDecoder->pred_statsce->channel) + return 33; /* intra channel prediction */ ic_prediction(ics, spec_coef, hDecoder->pred_statsce->channel, hDecoder->frameLength, @@ -1022,6 +1036,9 @@ } #endif + if (!hDecoder->lt_pred_statsce->channel) + return 34; + /* long term prediction */ lt_prediction(ics, &(ics->ltp), spec_coef, hDecoder->lt_pred_statsce->channel, hDecoder->fb, ics->window_shape, hDecoder->window_shape_prevsce->channel, @@ -1226,6 +1243,9 @@ /* MAIN object type prediction */ if (hDecoder->object_type == MAIN) { + if (!hDecoder->pred_statcpe->channel || !hDecoder->pred_statcpe->paired_channel) + return 33; + /* intra channel prediction */ ic_prediction(ics1, spec_coef1, hDecoder->pred_statcpe->channel, hDecoder->frameLength, hDecoder->sf_index); @@ -1264,6 +1284,9 @@ } #endif + if (!hDecoder->lt_pred_statcpe->channel || !hDecoder->lt_pred_statcpe->paired_channel) + return 34; + /* long term prediction */ lt_prediction(ics1, ltp1, spec_coef1, hDecoder->lt_pred_statcpe->channel, hDecoder->fb, ics1->window_shape, hDecoder->window_shape_prevcpe->channel,
View file
_service:obs_scm:faad2-2.11.2.obscpio/libfaad/ssr.c -> _service:obs_scm:faad2-2.11.3.obscpio/libfaad/ssr.c
Changed
@@ -37,6 +37,11 @@ #include "filtbank.h" #include "ssr.h" #include "ssr_fb.h" +#include "ssr_ipqf.h" + +static void ssr_gc_function(ssr_info *ssr, real_t *prev_fmd, + real_t *gc_function, uint8_t window_sequence, + uint16_t frame_len); void ssr_decode(ssr_info *ssr, fb_info *fb, uint8_t window_sequence, uint8_t window_shape, uint8_t window_shape_prev, @@ -90,7 +95,7 @@ if (window_sequence != EIGHT_SHORT_SEQUENCE) { ssr_gc_function(ssr, &prev_fmdband * frame_len*2, - gc_function, window_sequence, band, frame_len); + gc_function, window_sequence, frame_len); for (i = 0; i < frame_len*2; i++) databand * frame_len*2 + i *= gc_functioni; @@ -136,7 +141,7 @@ static void ssr_gc_function(ssr_info *ssr, real_t *prev_fmd, real_t *gc_function, uint8_t window_sequence, - uint8_t band, uint16_t frame_len) + uint16_t frame_len) { uint16_t i; uint16_t len_area1, len_area2;
View file
_service:obs_scm:faad2-2.11.2.obscpio/properties.json -> _service:obs_scm:faad2-2.11.3.obscpio/properties.json
Changed
@@ -1,4 +1,4 @@ { "//": "This file contains properties used in build / release process", - "PACKAGE_VERSION": "2.11.2" + "PACKAGE_VERSION": "2.11.3" }
View file
_service:obs_scm:faad2.obsinfo
Changed
@@ -1,4 +1,4 @@ name: faad2 -version: 2.11.2 -mtime: 1774434870 -commit: f2f4e8e8093df276fb1f6f96eb69efd37aba3da3 +version: 2.11.3 +mtime: 1787118336 +commit: 6918ebb51b8f7e86278da15884bd7114e4b9661e
Locations
Projects
Search
Status Monitor
Help
Open Build Service
OBS Manuals
API Documentation
OBS Portal
Reporting a Bug
Contact
Mailing List
Forums
Chat (IRC)
Twitter
Open Build Service (OBS)
is an
openSUSE project
.