avcodec/screenpresso: reject deflate output shorter than the frame

Fixes: use of uninitialized memory
Fixes: screenpresso_short_zlib_heap_disclosure.avi
Fixes: ksUBwBOjJodq
Found-by: Adrian Junge (vurlo)
This commit is contained in:
Michael Niedermayer
2026-07-22 05:44:41 +02:00
committed by michaelni
parent 7002e01c19
commit 7058900614

View File

@@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame,
return AVERROR_INVALIDDATA;
}
/* Codec has aligned strides */
src_linesize = FFALIGN(avctx->width * component_size, 4);
/* Inflate the frame after the 2 byte header */
ret = uncompress(ctx->inflated_buf, &length,
avpkt->data + 2, avpkt->size - 2);
@@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame,
av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret);
return AVERROR_UNKNOWN;
}
if (length < src_linesize * avctx->height) {
av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n",
length, src_linesize * avctx->height);
return AVERROR_INVALIDDATA;
}
ret = ff_reget_buffer(avctx, ctx->current, 0);
if (ret < 0)
return ret;
/* Codec has aligned strides */
src_linesize = FFALIGN(avctx->width * component_size, 4);
/* When a keyframe is found, copy it (flipped) */
if (keyframe)
av_image_copy_plane(ctx->current->data[0] +