From 273b161a98bcd918b47397b6a3e1bcc46aefcf67 Mon Sep 17 00:00:00 2001 From: Hassan Hany Date: Wed, 4 Feb 2026 02:47:57 +0200 Subject: [PATCH] avcodec/exif: skip EXIF entries with invalid TIFF field type 0 EXIF IFD entries with TIFF field type 0 are invalid per the specification. Without a check, exif_read_values() fails to allocate entry->value, causing an out of memory error. This patch skips such entries early during parsing, allowing decoding to continue normally. Fixes: https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21623 --- libavcodec/exif.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/libavcodec/exif.c b/libavcodec/exif.c index 01ffa88194..a184733e80 100644 --- a/libavcodec/exif.c +++ b/libavcodec/exif.c @@ -494,6 +494,11 @@ static int exif_decode_tag(void *logctx, GetByteContext *gb, int le, av_log(logctx, AV_LOG_DEBUG, "TIFF Tag: id: 0x%04x, type: %d, count: %u, offset: %d, " "payload: %" PRIu32 "\n", entry->id, type, count, tell, payload); + if (!type) { + av_log(logctx, AV_LOG_DEBUG, "Skipping invalid TIFF tag 0\n"); + goto end; + } + /* AV_TIFF_IFD is the largest, numerically */ if (type > AV_TIFF_IFD || count >= INT_MAX/8U) return AVERROR_INVALIDDATA;