Commit 10306e9c authored by Vittorio Giovara's avatar Vittorio Giovara

jpeg2000: fix dereferencing invalid pointers during cleanup

CC: libav-stable@libav.org
Found-by: 's avatarLaurent Butti <laurentb@gmail.com>
Signed-off-by: 's avatarVittorio Giovara <vittorio.giovara@gmail.com>
parent ab72eda1
...@@ -229,7 +229,7 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp, ...@@ -229,7 +229,7 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp,
if (!comp->i_data) if (!comp->i_data)
return AVERROR(ENOMEM); return AVERROR(ENOMEM);
} }
comp->reslevel = av_malloc_array(codsty->nreslevels, sizeof(*comp->reslevel)); comp->reslevel = av_mallocz_array(codsty->nreslevels, sizeof(*comp->reslevel));
if (!comp->reslevel) if (!comp->reslevel)
return AVERROR(ENOMEM); return AVERROR(ENOMEM);
/* LOOP on resolution levels */ /* LOOP on resolution levels */
...@@ -277,7 +277,7 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp, ...@@ -277,7 +277,7 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp,
reslevel->log2_prec_height) - reslevel->log2_prec_height) -
(reslevel->coord[1][0] >> reslevel->log2_prec_height); (reslevel->coord[1][0] >> reslevel->log2_prec_height);
reslevel->band = av_malloc_array(reslevel->nbands, sizeof(*reslevel->band)); reslevel->band = av_mallocz_array(reslevel->nbands, sizeof(*reslevel->band));
if (!reslevel->band) if (!reslevel->band)
return AVERROR(ENOMEM); return AVERROR(ENOMEM);
...@@ -373,9 +373,9 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp, ...@@ -373,9 +373,9 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp,
for (j = 0; j < 2; j++) for (j = 0; j < 2; j++)
band->coord[1][j] = ff_jpeg2000_ceildiv(band->coord[1][j], dy); band->coord[1][j] = ff_jpeg2000_ceildiv(band->coord[1][j], dy);
band->prec = av_malloc_array(reslevel->num_precincts_x * band->prec = av_mallocz_array(reslevel->num_precincts_x *
reslevel->num_precincts_y, reslevel->num_precincts_y,
sizeof(*band->prec)); sizeof(*band->prec));
if (!band->prec) if (!band->prec)
return AVERROR(ENOMEM); return AVERROR(ENOMEM);
...@@ -488,15 +488,30 @@ void ff_jpeg2000_cleanup(Jpeg2000Component *comp, Jpeg2000CodingStyle *codsty) ...@@ -488,15 +488,30 @@ void ff_jpeg2000_cleanup(Jpeg2000Component *comp, Jpeg2000CodingStyle *codsty)
for (reslevelno = 0; for (reslevelno = 0;
comp->reslevel && reslevelno < codsty->nreslevels; comp->reslevel && reslevelno < codsty->nreslevels;
reslevelno++) { reslevelno++) {
Jpeg2000ResLevel *reslevel = comp->reslevel + reslevelno; Jpeg2000ResLevel *reslevel;
if (!comp->reslevel)
continue;
reslevel = comp->reslevel + reslevelno;
for (bandno = 0; bandno < reslevel->nbands; bandno++) { for (bandno = 0; bandno < reslevel->nbands; bandno++) {
Jpeg2000Band *band = reslevel->band + bandno; Jpeg2000Band *band;
if (!reslevel->band)
continue;
band = reslevel->band + bandno;
for (precno = 0; precno < reslevel->num_precincts_x * reslevel->num_precincts_y; precno++) { for (precno = 0; precno < reslevel->num_precincts_x * reslevel->num_precincts_y; precno++) {
Jpeg2000Prec *prec = band->prec + precno; Jpeg2000Prec *prec;
if (!band->prec)
continue;
prec = band->prec + precno;
av_freep(&prec->zerobits); av_freep(&prec->zerobits);
av_freep(&prec->cblkincl); av_freep(&prec->cblkincl);
av_freep(&prec->cblk); av_freep(&prec->cblk);
} }
av_freep(&band->prec); av_freep(&band->prec);
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment