avcodec/lcldec: zero the not-decoded tail to avoid heap disclosure

Fixes: use of uninitialized memory
Fixes: CsNDKB1K1U0C
Fixes: e2c3aa8e2b (avcodec/lcldec: More space for rgb24)
Found-by: Adrian Junge (vurlo)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit e7cbfd1c50)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
Michael Niedermayer
2026-06-28 19:04:07 +02:00
parent c20d78c683
commit 7c0b8c8594

View File

@@ -120,6 +120,9 @@ static unsigned int mszh_decomp(const unsigned char * srcptr, int srclen, unsign
}
}
if (destptr < destptr_end)
memset(destptr, 0, destptr_end - destptr);
return destptr - destptr_bak;
}
@@ -153,8 +156,11 @@ static int zlib_decomp(AVCodecContext *avctx, const uint8_t *src, int src_len, i
if (expected != (unsigned int)zstream->total_out) {
av_log(avctx, AV_LOG_ERROR, "Decoded size differs (%d != %lu)\n",
expected, zstream->total_out);
if (expected > (unsigned int)zstream->total_out)
if (expected > (unsigned int)zstream->total_out) {
memset(c->decomp_buf + offset + zstream->total_out, 0,
c->decomp_size - offset - zstream->total_out);
return (unsigned int)zstream->total_out;
}
return AVERROR_UNKNOWN;
}
return zstream->total_out;