From patchwork Fri Mar 4 21:09:39 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Paul B Mahol X-Patchwork-Id: 34615 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a05:6838:d078:0:0:0:0 with SMTP id x24csp2000445nkx; Fri, 4 Mar 2022 13:08:14 -0800 (PST) X-Google-Smtp-Source: ABdhPJxkBLnYvsC/aGejZFpjVY6GnZdIoIoh7M5Njiwh2UFhGdK5Edo8T9/vFrh94bf4FTqHm9AV X-Received: by 2002:a17:906:2ec6:b0:69f:286a:66ab with SMTP id s6-20020a1709062ec600b0069f286a66abmr525945eji.684.1646428094217; Fri, 04 Mar 2022 13:08:14 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1646428094; cv=none; d=google.com; s=arc-20160816; b=NGjZMAdaNQnz8v6O4YgN6g2JM80Z3aRNnCH2sP0FJXfelP0cth3IkrQ+cyN+B/f4Xo u4QB7aGLt3R4dxkuzjX7aReDFiSrcUgo81nUOPz5nLn33myOyk2yRL+y1zhx4kMHTWH/ wWvl/qrAO5wwRIlJutemZETd2rX/Tb7S1DJPb+RbgZi2O6D3xSsEMekh6DiZhekpnFNW DXvdR9gfc4VXyCiwULiYtk6e/c1XN4foQYyfvZMGRDYuEL72UJoD2sPblG91b3OsDUYk 18xP5PSPM023jXRxBHR0zZDfjXHIRbGdZe9cWciDubZsPkjzzQJYDv+IAwJyxrFQ6ODF wSJw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:message-id:date:to:from :dkim-signature:delivered-to; bh=WNxqM+iujmHgd5NlFKvfIMiNrWVosqpDmKWQBt63eXk=; b=YQimZQTxRB5gbdBfZ+jgtqERD1ZATGzU2aB+NHh6++snQ3SQMIsKckrj5wYRsJN9W3 3gjuwGJIWGKD6d/srx3ki/oiMpdCuf/wCoT7kWfDv/GmoJDr96R2gUPW+6TVUNyI0Zvi ytosf9UmLCiTJc/WBQ2KspF37qfTXreh3slKeO0zFlJgO0IP13J55Li3y5yY0E/t5dG2 CPxpH/s1wh8bCW4FlM4/mpj4z8L9lpriSJaMb++8wKCD7YB1uqG+a28ACTl0FXG+jdMw sXeVSdxLYn8zFcIIDrv8fuiXN3V86jNH3UmlmMOxm/ocKzoOUbcmBgi0QxoC+Zx7wd8u M/IA== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=CqHvqgZ3; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id m22-20020a056402431600b00415c8fb52edsi4136464edc.171.2022.03.04.13.08.13; Fri, 04 Mar 2022 13:08:14 -0800 (PST) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=CqHvqgZ3; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id E368568B181; Fri, 4 Mar 2022 23:08:09 +0200 (EET) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from mail-ej1-f46.google.com (mail-ej1-f46.google.com [209.85.218.46]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 00C68680064 for ; Fri, 4 Mar 2022 23:08:02 +0200 (EET) Received: by mail-ej1-f46.google.com with SMTP id kt27so20028153ejb.0 for ; Fri, 04 Mar 2022 13:08:02 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=IY1P0IT11oKxOJOgxBLfEzmERPgIY82SwhcctD/mej0=; b=CqHvqgZ3ZQfq5rjgwvgWg0HHvLqFpxbgveeNx8pl73CVE31L1mvdQsMcUYklCXp0Fr YyteNh/mysIelU23WN5K14iIpYU2Qw1+xozUuHUIKOoNI/b6kJ7SwQG0gtxR213VBYaF 9MCKUNQyJ+r1wGymIHlxVS5q00ExrpiSwq8xmk7I9vxvIbVYP/rELdIFD1LACcsN3EDq mm6OuJUngghOy/p0eM+uMHjKqhG956ou8IeNJyUF8GXGy7VsJ75y4VS/4F6xTiDanOAU 9taWwMPf/li5o/2zzA8h26+GKXPYI5aHIz8RZ6lvQ+j1rOM3PioCj9DNsOaUj8KqnL8Y O5Dg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=IY1P0IT11oKxOJOgxBLfEzmERPgIY82SwhcctD/mej0=; b=ho+mPPB642I0spJ+s1keeq2He2oLzunjhkd0abvMg84Okhzobt4JL1yJHxVLvO0AIa G8wteg7h0t23Ba7nGoEn/jmh73CN/eUL9dZj7ruDClzlzrhGq8R++qq0OMTrB91s5UML F2WT/VnEpH3K1CGHTueE6u272caSdQJq7z9VRDbSiLTkD5xFPsxzYNHBotC1/HxTpOVM wCieVENOtvoy29ACy4RJaaNdtdDycRcaIH65cOKobfJZbHqyVFObYEqunAWJ6RyCcGOh VcE2nxh4UVB7gWY4PPZ2T2yJFyPbdWZ2Dr43VZYIonmfNfeh/EzlAj4UnrTd6R6OPwDx rCiA== X-Gm-Message-State: AOAM5315TM9CT/qCcHV+YYKn+I4yLoWsHIt4S0H76GnWcfXkG+BdyI7d 7B7/3Ofpre6c0uij4oV/4EhpZbvxUXc= X-Received: by 2002:a17:906:7953:b0:6da:951c:1173 with SMTP id l19-20020a170906795300b006da951c1173mr510071ejo.465.1646428082435; Fri, 04 Mar 2022 13:08:02 -0800 (PST) Received: from localhost.localdomain ([212.15.177.18]) by smtp.gmail.com with ESMTPSA id i21-20020a1709061cd500b006da62ab503csm2122778ejh.157.2022.03.04.13.08.01 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 04 Mar 2022 13:08:01 -0800 (PST) From: Paul B Mahol To: ffmpeg-devel@ffmpeg.org Date: Fri, 4 Mar 2022 22:09:39 +0100 Message-Id: <20220304210939.468116-1-onemda@gmail.com> X-Mailer: git-send-email 2.33.0 MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH] avcodec/dnxhdenc: add checks for write overflows X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: XtFdC0PMaVU1 Also add compensation for extra data needed per packet. Signed-off-by: Paul B Mahol --- libavcodec/dnxhdenc.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/libavcodec/dnxhdenc.c b/libavcodec/dnxhdenc.c index ac92474e56..cba3a753e5 100644 --- a/libavcodec/dnxhdenc.c +++ b/libavcodec/dnxhdenc.c @@ -1220,7 +1220,7 @@ static int dnxhd_encode_fast(AVCodecContext *avctx, DNXHDEncContext *ctx) avctx->execute2(avctx, dnxhd_mb_var_thread, NULL, NULL, ctx->m.mb_height); radix_sort(ctx->mb_cmp, ctx->mb_cmp_tmp, ctx->m.mb_num); - for (x = 0; x < ctx->m.mb_num && max_bits > ctx->frame_bits; x++) { + for (x = 0; x < ctx->m.mb_num && max_bits > ctx->frame_bits - ctx->m.mb_num * 2; x++) { int mb = ctx->mb_cmp[x].mb; int rc = (ctx->qscale * ctx->m.mb_num ) + mb; max_bits -= ctx->mb_rc[rc].bits - @@ -1228,6 +1228,9 @@ static int dnxhd_encode_fast(AVCodecContext *avctx, DNXHDEncContext *ctx) ctx->mb_qscale[mb] = ctx->qscale + 1; ctx->mb_bits[mb] = ctx->mb_rc[rc + ctx->m.mb_num].bits; } + + if ((max_bits >> 3) > (ctx->frame_bits >> 3) - ctx->data_offset - 4) + return AVERROR(EINVAL); } return 0; }