From e9a759544b7a42991e12f7f3c8bf6768679f46d0 Mon Sep 17 00:00:00 2001 From: Dirk Farin Date: Tue, 5 Apr 2022 18:41:28 +0200 Subject: [PATCH] [PATCH] fix streams where SPS image size changes without refreshing PPS (#299) Gbp-Pq: Name 0005-CVE-2021-36408.patch --- libde265/decctx.cc | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/libde265/decctx.cc b/libde265/decctx.cc index edebb71..6701725 100644 --- a/libde265/decctx.cc +++ b/libde265/decctx.cc @@ -562,6 +562,15 @@ de265_error decoder_context::read_sps_NAL(bitreader& reader) sps[ new_sps->seq_parameter_set_id ] = new_sps; + // Remove the all PPS that referenced the old SPS because parameters may have changed and we do not want to + // get the SPS and PPS parameters (e.g. image size) out of sync. + + for (auto& p : pps) { + if (p && p->seq_parameter_set_id == new_sps->seq_parameter_set_id) { + p = nullptr; + } + } + return DE265_OK; } -- 2.30.2