← All tasks
cppf4exb/sdrangel #2766Not a task: not reproduced

Bundled faad2 is 2.8.8 (pre-fix) — excluded_channels heap overflow

envgap__f4exb__sdrangel-2766

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
8fb29c9ddd79afe4afa09defa906ea1116c9e209
Manifest
external/CMakeLists.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

f4exb/sdrangel #2766 · read the original issue
external/CMakeLists.txt fetches faad2 2.8.8 (ExternalProject URL), which is before the 2.9.0 fix (commit 942c3e0a) for a heap overflow in excluded_channels(): the DRC parser's exclude_mask write loop has no MAX_CHANNELS bound, so a FIL/DRC extension payload with enough additional_excluded_chns=1 bits writes past the drc_info allocation.

The DAB demodulator feeds DAB+ AAC access units to NeAACDecDecode(), which runs this parser per frame on attacker-controlled broadcast/recorded input.

Fix: bump the fetched faad2 to >= 2.9.0. 2.9.x still uses the autotools configure build, so the existing CONFIGURE_COMMAND keeps working; 2.10+ moved to CMake and would need the ExternalProject build commands changed too. The bundled copy is built only when no system faad2 is used, so this affects the Windows/macOS binaries and source-fallback builds.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]