PR #24597 opened by michaelni URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24597 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24597.patch
Fixes: 1j9froqh2wEw Regression since: 2ad405548b754751a33f7d8532604eae7fe4ce54 Fixes: use-of-uninitialized-value Found-by: Trithem90 <[email protected]> # Summary of changes Briefly describe what this PR does and why. <!-- If this PR requires new FATE test samples, attach them to the PR and list their target paths below (relative to the fate-suite root). Attached filenames must match the sample's filename: ```fate-samples # e.g. vorbis/new-sample.ogg ``` --> >From 9a8ca916f11d7bda8e3ddab91065788f5c229f4d Mon Sep 17 00:00:00 2001 From: Trithem90 <[email protected]> Date: Tue, 1 Sep 2026 21:44:45 +0200 Subject: [PATCH] avcodec/targa: reject truncated RLE packet payloads Fixes: 1j9froqh2wEw Regression since: 2ad405548b754751a33f7d8532604eae7fe4ce54 Fixes: use-of-uninitialized-value Found-by: Trithem90 <[email protected]> --- libavcodec/targa.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/libavcodec/targa.c b/libavcodec/targa.c index 7e016ea4af..825442adf9 100644 --- a/libavcodec/targa.c +++ b/libavcodec/targa.c @@ -69,7 +69,11 @@ static int targa_decode_rle(AVCodecContext *avctx, TargaContext *s, if (!type) { do { int n = FFMIN(count, w - x); - bytestream2_get_buffer(&s->gb, dst, n * depth); + if (bytestream2_get_buffer(&s->gb, dst, n * depth) != n * depth) { + av_log(avctx, AV_LOG_ERROR, + "Not enough data for raw RLE packet\n"); + return AVERROR_INVALIDDATA; + } count -= n; dst += n * depth; x += n; @@ -80,7 +84,11 @@ static int targa_decode_rle(AVCodecContext *avctx, TargaContext *s, } while (dst && count > 0); } else { uint8_t tmp[4]; - bytestream2_get_buffer(&s->gb, tmp, depth); + if (bytestream2_get_buffer(&s->gb, tmp, depth) != depth) { + av_log(avctx, AV_LOG_ERROR, + "Not enough data for RLE pixel\n"); + return AVERROR_INVALIDDATA; + } do { int n = FFMIN(count, w - x); count -= n; -- 2.52.0 _______________________________________________ ffmpeg-devel mailing list -- [email protected] To unsubscribe send an email to [email protected]
