avformat/mov: cap HEIF ICC profile copies via c*max_streams to bound CPU and memory

Found-by: Claude (Anthropic). Human-verified and reported by
Omkhar Arasaratnam <omkhar@linkedin.com>.
Signed-off-by: Omkhar Arasaratnam <omkhar@linkedin.com>
This commit is contained in:
Omkhar Arasaratnam
2026-05-21 00:00:00 +00:00
committed by michaelni
parent 344a9ce2da
commit 711cdae64f
2 changed files with 8 additions and 0 deletions

View File

@@ -391,6 +391,7 @@ typedef struct MOVContext {
int64_t idat_offset;
int interleaved_read;
AVDictionary* decryption_keys;
unsigned heif_icc_profile_items;
} MOVContext;
int ff_mp4_read_descr_len(AVIOContext *pb);

View File

@@ -2146,6 +2146,12 @@ static int mov_read_colr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
return AVERROR(ENOMEM);
icc_profile = sd->data;
} else {
if (c->heif_icc_profile_items >= c->fc->max_streams) {
av_log(c->fc, AV_LOG_WARNING,
"HEIF ICC profile copies exceed cap %d; ignoring further items\n",
c->fc->max_streams);
return 0;
}
av_freep(&item->icc_profile);
icc_profile = item->icc_profile = av_malloc(atom.size - 4);
if (!icc_profile) {
@@ -2153,6 +2159,7 @@ static int mov_read_colr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
return AVERROR(ENOMEM);
}
item->icc_profile_size = atom.size - 4;
c->heif_icc_profile_items++;
}
ret = ffio_read_size(pb, icc_profile, atom.size - 4);
if (ret < 0)