Bundled faad2 is 2.8.8 (pre-fix) — excluded_channels heap overflow
envgap__f4exb__sdrangel-2766
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
8fb29c9ddd79afe4afa09defa906ea1116c9e209- Manifest
external/CMakeLists.txt- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
f4exb/sdrangel #2766 · read the original issue
external/CMakeLists.txt fetches faad2 2.8.8 (ExternalProject URL), which is before the 2.9.0 fix (commit 942c3e0a) for a heap overflow in excluded_channels(): the DRC parser's exclude_mask write loop has no MAX_CHANNELS bound, so a FIL/DRC extension payload with enough additional_excluded_chns=1 bits writes past the drc_info allocation. The DAB demodulator feeds DAB+ AAC access units to NeAACDecDecode(), which runs this parser per frame on attacker-controlled broadcast/recorded input. Fix: bump the fetched faad2 to >= 2.9.0. 2.9.x still uses the autotools configure build, so the existing CONFIGURE_COMMAND keeps working; 2.10+ moved to CMake and would need the ExternalProject build commands changed too. The bundled copy is built only when no system faad2 is used, so this affects the Windows/macOS binaries and source-fallback builds.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]