This is an automated email from the git hooks/post-receive script.
Git pushed a commit to branch master
in repository ffmpeg.
The following commit(s) were added to refs/heads/master by this push:
new 7058900614 avcodec/screenpresso: reject deflate output shorter than
the frame
7058900614 is described below
commit 705890061467ad550ecc1dad5eea07f28ccfb43e
Author: Michael Niedermayer <[email protected]>
AuthorDate: Wed Jul 22 05:44:41 2026 +0200
Commit: michaelni <[email protected]>
CommitDate: Mon Jul 27 03:33:28 2026 +0000
avcodec/screenpresso: reject deflate output shorter than the frame
Fixes: use of uninitialized memory
Fixes: screenpresso_short_zlib_heap_disclosure.avi
Fixes: ksUBwBOjJodq
Found-by: Adrian Junge (vurlo)
---
libavcodec/screenpresso.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/libavcodec/screenpresso.c b/libavcodec/screenpresso.c
index b27154991c..5864253d41 100644
--- a/libavcodec/screenpresso.c
+++ b/libavcodec/screenpresso.c
@@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx,
AVFrame *frame,
return AVERROR_INVALIDDATA;
}
+ /* Codec has aligned strides */
+ src_linesize = FFALIGN(avctx->width * component_size, 4);
+
/* Inflate the frame after the 2 byte header */
ret = uncompress(ctx->inflated_buf, &length,
avpkt->data + 2, avpkt->size - 2);
@@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext
*avctx, AVFrame *frame,
av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret);
return AVERROR_UNKNOWN;
}
+ if (length < src_linesize * avctx->height) {
+ av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n",
+ length, src_linesize * avctx->height);
+ return AVERROR_INVALIDDATA;
+ }
ret = ff_reget_buffer(avctx, ctx->current, 0);
if (ret < 0)
return ret;
- /* Codec has aligned strides */
- src_linesize = FFALIGN(avctx->width * component_size, 4);
-
/* When a keyframe is found, copy it (flipped) */
if (keyframe)
av_image_copy_plane(ctx->current->data[0] +
_______________________________________________
ffmpeg-cvslog mailing list -- [email protected]
To unsubscribe send an email to [email protected]