Skip to content

EbmlMaster: fix invalid reads#352

Merged
mbunkus merged 3 commits into
Matroska-Org:masterfrom
robUx4:master-sec
Jul 24, 2026
Merged

EbmlMaster: fix invalid reads#352
mbunkus merged 3 commits into
Matroska-Org:masterfrom
robUx4:master-sec

Conversation

@robUx4

@robUx4 robUx4 commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

missing "backports" of #338, #341, and #322

Reported-by: Benjamin Ali (glitchfox) glitchfox@benjaminali.com

robUx4 added 3 commits July 23, 2026 13:38
We found an upper element and there is not data to read after the current
element within its parent. That upper element is misplaced and should be
discarded.
The last element is truncated and doesn't contain the rest of its data.
When an element from an upper level is found we go up the caller chain,
passing the found element but it was not actually used (added to a list or freed).

This patch allows setting that element as the ElementLevelA found in the loop.
We skip the call the inDataStream.FindNextElement() to find it.

The new MaxSizeToRead is the size to read in the next inDataStream.FindNextElement() call.

The old MaxSizeToRead <= 0 code seems bogus as it would exit the loop
to find elements for that EbmlMaster even though there might still be elements to read.
…arent

It could be a file with missing data in the middle.
And we shouldn't use a MaxSizeToRead that would be negative.

Missing backport to master
Reported-by: Benjamin Ali (glitchfox) <glitchfox@benjaminali.com>
@robUx4 robUx4 added the bug label Jul 23, 2026
@mbunkus
mbunkus merged commit c37b009 into Matroska-Org:master Jul 24, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants