From patchwork Tue May 31 12:41:04 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Ronald S. Bultje" X-Patchwork-Id: 36011 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a05:6a20:6914:b0:82:6b11:2509 with SMTP id q20csp2806120pzj; Tue, 31 May 2022 05:41:19 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxDc9t+sFJp8CmEhNolFLAwBBwBP+Rq002briYcPnhhE12UxHQgNnBt1vmFc4FLQ0Tcq3cz X-Received: by 2002:aa7:db02:0:b0:42d:c3ba:9c86 with SMTP id t2-20020aa7db02000000b0042dc3ba9c86mr15715515eds.337.1654000879761; Tue, 31 May 2022 05:41:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1654000879; cv=none; d=google.com; s=arc-20160816; b=OcmgMh7yOk1KBTBLhsR2B9vMXwG/C0S8RYz/L9gVgnUBwA5HiWTxJhDo+ELRhOQNGi FS68xxMsGxyq2HBLx7cBagcJzP0XG5jnVy3zLhSTMts/pSSqt+gL//n1DPXS7l0SBDjF MAwJoXNGupvl8EBJSvqO0wjNEAqN+EStyXoq8AnS7XLkAxY/3wCwa0f+l9FJk5W5cbnB GY7/lkUIhsRgVhGzqyXGZuwlZ30Rc0bAqlCEC3myeGVXwZSNIJtYAwAHUQotUFQeF+pf ASAKbkxVIHanRnn1gOZ3H5KRUtc9w2GeLTOwk2JOHGNFMT6EH9Nmo/LQiio5KG5KrIRd C3Ww== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:content-transfer-encoding:cc:reply-to :list-subscribe:list-help:list-post:list-archive:list-unsubscribe :list-id:precedence:subject:mime-version:references:in-reply-to :message-id:date:to:from:dkim-signature:delivered-to; bh=Q/pdrpzeXHtlUCppr3gzz95/nRqTwcs4GTIJexVLWKE=; b=nNE/k5UscJY8bsiA/olBFcObOcWU5uoxgtRgUXDhCBEHDP9f9t4xFru41O37iMw9T5 kq+HCUZDptAQ6S4rPY4UJAgeiAoIadaWm0Xz8oxB9yv3mWFJymQ2bjto7GU+Fo4zoLNI 30aUcYburOtq9i1dmUKVghFK+pjbuHKT3ER7nHK2nzsPKlnkBFmXNbf3K9hwG0tWnRZ/ +j8RlBumev+qweHQyY6rNHbGAsVJNSjNmUvAfrOWNPrOCAo7/c/w/n/KmKSWq4toa7we EInvCFi6QngLGeGKtiHTzp0+fjSQW3pL3wZb93uY8MRwYJuQltjZyIi+R8Oi6z3IlMLM 2KrQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=ixX+X9wu; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id v8-20020aa7d648000000b004285db05e3csi14256235edr.87.2022.05.31.05.41.18; Tue, 31 May 2022 05:41:19 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=ixX+X9wu; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 93E5568B6A0; Tue, 31 May 2022 15:41:15 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from mail-qt1-f172.google.com (mail-qt1-f172.google.com [209.85.160.172]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 3BD8468B4E6 for ; Tue, 31 May 2022 15:41:09 +0300 (EEST) Received: by mail-qt1-f172.google.com with SMTP id x20so4817402qtp.8 for ; Tue, 31 May 2022 05:41:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=F043f6pLZqzQhV+C0pm2Fih/XkcW3bsMNxYSeFz3E3o=; b=ixX+X9wuxBCkF/PxklXvRlMg+47yd5mpYIWnwFLYYwBU+QURE7W/+Dyp37JrWoWuqu 4bZ9T2XhJC2RfzNMLxGpP3wBDQS5cqkCtk67RlYolDUQs/Ns0qG4exE8ezgxaEDXwxQK +JyDyeA1hssFD03SPozzK/9jUPtKnKMyWxsW26popPQl9/8TgG+U2+spnSMbYHBqUhog 8nRDvo38XO+mA7qIb+XYoGVt/+8MJkIkqyaN79WZZCHMUfzse/S2cKCmJ7yEA36Sg2K2 rOlLxNSLW8gucAV4sWzhzzDPPZQHJOLWCTbosHfym1SeI7KbOnfVXDEAf1O58k1b9hZi +2VQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=F043f6pLZqzQhV+C0pm2Fih/XkcW3bsMNxYSeFz3E3o=; b=H0nOHgfiytqBPWuR9Jp0OwLRQwp/8wBUvedFwF773TuI/aYPDp+LiWzu+fh5ttFPst J8XJWusUore5DLWWOfZC/WG84TKVyUdCAS8UPAblQkWmU7q7FanwTcOczBVxri1he+Bv 6wfo/Ugvc/MUtC7j95kjtVm56vp97yDS0waiJUr77xejWjkyfEL9wxpblPUeGcLbQVd2 7s1nXV99c8YkpilWCf1UVtLGcedPtfeq5P1vF8UlJ24E74bVprQhSbbkQCMvG4Z/fRuH Qj30JWbkMMEiK2nXmWw/wtEWZaaeYb7xBGeOl72p2DEGMry9bY3gMnwSJ0uyh45lZp7B 4yrA== X-Gm-Message-State: AOAM530+D2l0H/wrexFH1bpMOKQ+GwJR9qc2W/a4krINeAsKzlQ78N6Y vN3ji/Feq7/jDxjplw2vXr2o/gZ+Ag0= X-Received: by 2002:ac8:5984:0:b0:304:ba53:17f2 with SMTP id e4-20020ac85984000000b00304ba5317f2mr2570258qte.366.1654000867200; Tue, 31 May 2022 05:41:07 -0700 (PDT) Received: from Ronalds-MBP.lan (2603-7000-3a03-6193-a1e6-678c-d9df-11f5.res6.spectrum.com. [2603:7000:3a03:6193:a1e6:678c:d9df:11f5]) by smtp.gmail.com with ESMTPSA id d141-20020a376893000000b0069fc13ce24asm9230294qkc.123.2022.05.31.05.41.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 May 2022 05:41:06 -0700 (PDT) From: "Ronald S. Bultje" To: ffmpeg-devel@ffmpeg.org Date: Tue, 31 May 2022 08:41:04 -0400 Message-Id: <20220531124104.56189-1-rsbultje@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20220531123147.56064-1-rsbultje@gmail.com> References: <20220531123147.56064-1-rsbultje@gmail.com> MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH] vp9: don't overread by 4 pixels in ff_vp9_avg4_mmxext(). X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Cc: "Ronald S. Bultje" Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: cfX64Pq9lYb5 If the block is at the end of the allocated buffer and there is no padding, this will over-read, which may cause crashes. Reported by Firefox. --- libavcodec/x86/vp9mc.asm | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/libavcodec/x86/vp9mc.asm b/libavcodec/x86/vp9mc.asm index f64161b2c2..f8b244b2fe 100644 --- a/libavcodec/x86/vp9mc.asm +++ b/libavcodec/x86/vp9mc.asm @@ -604,12 +604,15 @@ cglobal vp9_%1%2 %+ %%szsuf, 5, 5, %8, dst, dstride, src, sstride, h %%pavg m0, [dstq] %%pavg m1, [dstq+d%3] %%pavg m2, [dstq+d%4] - %%pavg m3, [dstq+d%5] %if %2/mmsize == 8 + %%pavg m3, [dstq+d%5] %%pavg m4, [dstq+mmsize*4] %%pavg m5, [dstq+mmsize*5] %%pavg m6, [dstq+mmsize*6] %%pavg m7, [dstq+mmsize*7] +%else + %%srcfn m4, [dstq+d%5] + %%pavg m3, m4 %endif %endif %%dstfn [dstq], m0