From patchwork Tue May 31 13:21:30 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Ronald S. Bultje" X-Patchwork-Id: 36012 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a05:6a20:6914:b0:82:6b11:2509 with SMTP id q20csp2828297pzj; Tue, 31 May 2022 06:21:47 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwkiFsoltqXuKki/1l82ZO8teiGOPWAkpoVWxwM1+4sjYD8kksB2DEo7h9OPK6Iko+1Myrd X-Received: by 2002:a17:907:6d12:b0:6fe:bef9:58d5 with SMTP id sa18-20020a1709076d1200b006febef958d5mr43486905ejc.548.1654003307455; Tue, 31 May 2022 06:21:47 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1654003307; cv=none; d=google.com; s=arc-20160816; b=dTehzctGrfv++pL4769RNqtykOTnxNE/nrYWSTAa3zudPRpF5QuucBx+bLJOexFayg K0QJ/M/2vneO0r4U1DJczzsj7eYmYYkyoEnuFG7xI8zE035iUbqt/IoTDkX7bYH3N/tX aUQJ9d0H654e7FfV6I/03txf6+iCg4DY+8o1wa0p7utPWO2YHhuJ1PQK1exT+v6hHEsH Osng9SBkSo6/FzWMJGx2OC0Zfmw5WkxaG9HkLt5FNf2VyJXSCLr5raCwiZRrhCIw0iHM pnpKoPOxb1GGR50RrQNWWG4GscXcfIZnqr5j6HxEd4Q3UCq/JEdXrtevnnlwf7kGOIOy +6Pw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:content-transfer-encoding:cc:reply-to :list-subscribe:list-help:list-post:list-archive:list-unsubscribe :list-id:precedence:subject:mime-version:references:in-reply-to :message-id:date:to:from:dkim-signature:delivered-to; bh=zxyRkaZZBmTkApMEMo7LdsCMqFkillLs5HPVZ49/sMQ=; b=bg5iZK8eHUiPjjM1m34o+TFjTRXzm6Zg5Tk/hdab9qoY1ZYXIaCgkm1L+36FUBz0SV oABcG0r48Iw9ip+J/WjkYs/LEJ1l431VFXLTPzP+yynICqN12B/Gup8gpyQxuIToFzCD FabXAUpDSk+v4Bb69HZg4Dmz2Mj6+bmt2OshfTpns5tHCnsAezcPfi/ClYLqUT/OoQu7 DtjW1jppVoUJm09bRxwF+HfE7BPM7j2wHFRUan0oEDw1YjkBR2qRYH+NYQ3not0FwTab /+gErn6w3OODWTmCWPidtncJ4Z3txT4tizyhEji+x2BKGlrc1I24XfFw4IuphyfjXjW6 rMZA== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=S64klOfc; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id k13-20020a1709065fcd00b006f3be13d016si13406934ejv.37.2022.05.31.06.21.46; Tue, 31 May 2022 06:21:47 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=S64klOfc; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id C73E268B6A3; Tue, 31 May 2022 16:21:42 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from mail-qk1-f172.google.com (mail-qk1-f172.google.com [209.85.222.172]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id DEE9068B636 for ; Tue, 31 May 2022 16:21:35 +0300 (EEST) Received: by mail-qk1-f172.google.com with SMTP id 190so13070450qkj.8 for ; Tue, 31 May 2022 06:21:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=xD8D+aQZt1X+i1iUM/ChR4p3LcmDdsQ+HwhW8EBoQNw=; b=S64klOfcS41gKsWvo4+rUcCVQ/8mayD4puQMTg1PH3uPix7KjE8p53FOUqy+HiYWWl in4jeZPAMI+6FfpyUQmJ8Ishg7ktOvEiGHx6aBRtExoPgRrj4X7NLwaPdStRTuBx+3xT xyLXF/Yvv7c2qyzKK9K6UwgJTUk8xeoFyHafEGZsn2PrR9k3Qs6v6+RIPDmRkxuRNXzz JFzHp9pDSNG0bm/vRrVmHTHVvXlnNLFbYGHG9yz/V7HohSyEjijAHyvYSM1CbdiQHuJC nzS1bljBvIrbN3K36zbv3vBaWlodxYz+pqdQo7f/tmz33YXoYXlmd0Vi2PBLevBbi0W6 Ow5A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=xD8D+aQZt1X+i1iUM/ChR4p3LcmDdsQ+HwhW8EBoQNw=; b=eo8i0Aon6F4W+YffwJu+Zj+tq5BUkSFdVRwxxfqL0WgFN+c3JXegX/V9m7wbz0w37j 3xloKurvn45dVPtuVa23zAjl63tu5sO1GNVnYVHo76n68sfzf0fLQaNfwdmDQDJ3nfb5 weONDwK0pq4xal5b03i6d/p4IIVk6qYtAMG+hZtvelN63ObtkSpEj1YMnbYxPuUGBFfe WBdJKkNDRujg/f2A8FF1ip+4wFeLhnQPcBfa5PSv+GSb4cB5X0EwWRxS/ezOGn904d6O eGwbnfQ48nB+Le+jIMH9MwB/RV+KaiY8kgL9lAOgfiVN16Tt/TU9dZi1GgFEoS9Lsi7T 67NQ== X-Gm-Message-State: AOAM530liCwx0iUduOnHxR1lNIkXxfguRsKEU0ktgUJvm8Ck2ENqrmQ5 Xd8q+CLx/57HeNYj6plW7RJ6eylBnGs= X-Received: by 2002:a37:a102:0:b0:6a3:5d5e:2706 with SMTP id k2-20020a37a102000000b006a35d5e2706mr34906543qke.251.1654003293946; Tue, 31 May 2022 06:21:33 -0700 (PDT) Received: from Ronalds-MBP.lan (2603-7000-3a03-6193-a1e6-678c-d9df-11f5.res6.spectrum.com. [2603:7000:3a03:6193:a1e6:678c:d9df:11f5]) by smtp.gmail.com with ESMTPSA id 73-20020a37064c000000b006a5d8d96681sm7558901qkg.100.2022.05.31.06.21.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 May 2022 06:21:33 -0700 (PDT) From: "Ronald S. Bultje" To: ffmpeg-devel@ffmpeg.org Date: Tue, 31 May 2022 09:21:30 -0400 Message-Id: <20220531132130.60467-1-rsbultje@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20220531124104.56189-1-rsbultje@gmail.com> References: <20220531124104.56189-1-rsbultje@gmail.com> MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH] vp9: don't overread by 4 pixels in ff_vp9_avg4_mmxext(). X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Cc: "Ronald S. Bultje" Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: Ab2nPvCL6mqN If the block is at the end of the allocated buffer and there is no padding, this will over-read, which may cause crashes. Reported by Firefox. --- libavcodec/x86/vp9mc.asm | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/libavcodec/x86/vp9mc.asm b/libavcodec/x86/vp9mc.asm index f64161b2c2..efc4cfbef1 100644 --- a/libavcodec/x86/vp9mc.asm +++ b/libavcodec/x86/vp9mc.asm @@ -604,7 +604,12 @@ cglobal vp9_%1%2 %+ %%szsuf, 5, 5, %8, dst, dstride, src, sstride, h %%pavg m0, [dstq] %%pavg m1, [dstq+d%3] %%pavg m2, [dstq+d%4] +%if %2 == 4 + %%srcfn m4, [dstq+d%5] + %%pavg m3, m4 +%else %%pavg m3, [dstq+d%5] +%endif %if %2/mmsize == 8 %%pavg m4, [dstq+mmsize*4] %%pavg m5, [dstq+mmsize*5]