From f9efbc7ba8bc596332322073f81d9dc5d2066558 Mon Sep 17 00:00:00 2001 From: MinnieTheMoocher Date: Sun, 27 Sep 2026 16:56:14 +0200 Subject: [PATCH] RIFF: Do not create INFO fields from a truncated chunk header (#1454) --- taglib/riff/wav/infotag.cpp | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/taglib/riff/wav/infotag.cpp b/taglib/riff/wav/infotag.cpp index f86a54ee..d76bf769 100644 --- a/taglib/riff/wav/infotag.cpp +++ b/taglib/riff/wav/infotag.cpp @@ -314,7 +314,8 @@ void RIFF::Info::Tag::setStringHandler(const StringHandler *handler) void RIFF::Info::Tag::parse(const ByteVector &data) { unsigned int p = 4; - while(p < data.size()) { + // Needs a full 8-byte header; fewer bytes left would wrap the check below. + while(p + 8 <= data.size()) { const unsigned int size = data.toUInt(p + 4, false); if(size > data.size() - p - 8) break;