avcodec/d3d12va_mpeg2: check size of frame bitstream against available buffer size

(cherry picked from commit 26a9f9b3ae)
This commit is contained in:
Timo Rothenpieler
2026-07-09 00:42:38 +02:00
committed by ffmpeg-devel
parent b19b023f2a
commit 865374b1ab

View File

@@ -90,6 +90,7 @@ static int d3d12va_mpeg2_decode_slice(AVCodecContext *avctx, const uint8_t *buff
static int update_input_arguments(AVCodecContext *avctx, D3D12_VIDEO_DECODE_INPUT_STREAM_ARGUMENTS *input_args, ID3D12Resource *buffer)
{
D3D12VADecodeContext *ctx = D3D12VA_DECODE_CONTEXT(avctx);
const MpegEncContext *s = avctx->priv_data;
D3D12DecodePictureContext *ctx_pic = s->cur_pic.ptr->hwaccel_picture_private;
@@ -105,6 +106,11 @@ static int update_input_arguments(AVCodecContext *avctx, D3D12_VIDEO_DECODE_INPU
.End = ctx_pic->bitstream_size,
};
if (ctx_pic->bitstream_size > ctx->bitstream_size) {
av_log(avctx, AV_LOG_ERROR, "Input frame bitstream size exceeds internal buffer!\n");
return AVERROR(EINVAL);
}
if (FAILED(ID3D12Resource_Map(buffer, 0, &range, &mapped_data))) {
av_log(avctx, AV_LOG_ERROR, "Failed to map D3D12 Buffer resource!\n");
return AVERROR(EINVAL);