As a brute-force approach, perhaps you could send the video through otherwise identical patched and unpatched emulators and compare post-playback memory and filesystem states?
It's also probably possible to extend the patches to detect malicious input.
Someone could probably also create a video with a payload to hot patch libstagefright.