PR #24596 opened by michaelni URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24596 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24596.patch
Introduced in e13eb58941. Fixes: out of array access Fixes: Oc4Zl8UslbKi Reported-identifier: swarm-fadegrays-transition-indexes-b-s-planes-with-a-s-linesize-815f04 Found-by: zhang xingxing <[email protected]> >From 8e2018ac32eb8dca21d04aefb14b7ebe15b26863 Mon Sep 17 00:00:00 2001 From: zhang xingxing <[email protected]> Date: Mon, 21 Sep 2026 06:14:36 +0200 Subject: [PATCH] avfilter/vf_xfade: fix fadegrays reading b's planes with a's linesize Introduced in e13eb58941. Fixes: out of array access Fixes: Oc4Zl8UslbKi Reported-identifier: swarm-fadegrays-transition-indexes-b-s-planes-with-a-s-linesize-815f04 Found-by: zhang xingxing <[email protected]> --- libavfilter/vf_xfade.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/libavfilter/vf_xfade.c b/libavfilter/vf_xfade.c index 53dcf3e1e5..fc1b35ebe4 100644 --- a/libavfilter/vf_xfade.c +++ b/libavfilter/vf_xfade.c @@ -1451,14 +1451,14 @@ static void fadegrays##name##_transition(AVFilterContext *ctx, const type *yf0 = (const type *)(a->data[0] + \ y * a->linesize[0]); \ const type *yf1 = (const type *)(b->data[0] + \ - y * a->linesize[0]); \ + y * b->linesize[0]); \ bg[0][0] = yf0[x]; \ bg[1][0] = yf1[x]; \ if (s->nb_planes == 4) { \ const type *af0 = (const type *)(a->data[3] + \ y * a->linesize[3]); \ const type *af1 = (const type *)(b->data[3] + \ - y * a->linesize[3]); \ + y * b->linesize[3]); \ bg[0][3] = af0[x]; \ bg[1][3] = af1[x]; \ } \ -- 2.52.0 _______________________________________________ ffmpeg-devel mailing list -- [email protected] To unsubscribe send an email to [email protected]
