Commit 1f8ff2b1 authored by Michael Niedermayer's avatar Michael Niedermayer Committed by Ronald S. Bultje

snow: check reference frame indices.

Fixes NULL ptr dereference

Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
CC: libav-stable@libav.org
Signed-off-by: 's avatarRonald S. Bultje <rsbultje@gmail.com>
parent c9837954
...@@ -132,7 +132,7 @@ static inline void decode_subband_slice_buffered(SnowContext *s, SubBand *b, sli ...@@ -132,7 +132,7 @@ static inline void decode_subband_slice_buffered(SnowContext *s, SubBand *b, sli
return; return;
} }
static void decode_q_branch(SnowContext *s, int level, int x, int y){ static int decode_q_branch(SnowContext *s, int level, int x, int y){
const int w= s->b_width << s->block_max_depth; const int w= s->b_width << s->block_max_depth;
const int rem_depth= s->block_max_depth - level; const int rem_depth= s->block_max_depth - level;
const int index= (x + y*w) << rem_depth; const int index= (x + y*w) << rem_depth;
...@@ -142,10 +142,11 @@ static void decode_q_branch(SnowContext *s, int level, int x, int y){ ...@@ -142,10 +142,11 @@ static void decode_q_branch(SnowContext *s, int level, int x, int y){
const BlockNode *tl = y && x ? &s->block[index-w-1] : left; const BlockNode *tl = y && x ? &s->block[index-w-1] : left;
const BlockNode *tr = y && trx<w && ((x&1)==0 || level==0) ? &s->block[index-w+(1<<rem_depth)] : tl; //FIXME use lt const BlockNode *tr = y && trx<w && ((x&1)==0 || level==0) ? &s->block[index-w+(1<<rem_depth)] : tl; //FIXME use lt
int s_context= 2*left->level + 2*top->level + tl->level + tr->level; int s_context= 2*left->level + 2*top->level + tl->level + tr->level;
int res;
if(s->keyframe){ if(s->keyframe){
set_blocks(s, level, x, y, null_block.color[0], null_block.color[1], null_block.color[2], null_block.mx, null_block.my, null_block.ref, BLOCK_INTRA); set_blocks(s, level, x, y, null_block.color[0], null_block.color[1], null_block.color[2], null_block.mx, null_block.my, null_block.ref, BLOCK_INTRA);
return; return 0;
} }
if(level==s->block_max_depth || get_rac(&s->c, &s->block_state[4 + s_context])){ if(level==s->block_max_depth || get_rac(&s->c, &s->block_state[4 + s_context])){
...@@ -168,17 +169,23 @@ static void decode_q_branch(SnowContext *s, int level, int x, int y){ ...@@ -168,17 +169,23 @@ static void decode_q_branch(SnowContext *s, int level, int x, int y){
}else{ }else{
if(s->ref_frames > 1) if(s->ref_frames > 1)
ref= get_symbol(&s->c, &s->block_state[128 + 1024 + 32*ref_context], 0); ref= get_symbol(&s->c, &s->block_state[128 + 1024 + 32*ref_context], 0);
if (ref >= s->ref_frames) {
av_log(s->avctx, AV_LOG_ERROR, "Invalid ref\n");
return AVERROR_INVALIDDATA;
}
pred_mv(s, &mx, &my, ref, left, top, tr); pred_mv(s, &mx, &my, ref, left, top, tr);
mx+= get_symbol(&s->c, &s->block_state[128 + 32*(mx_context + 16*!!ref)], 1); mx+= get_symbol(&s->c, &s->block_state[128 + 32*(mx_context + 16*!!ref)], 1);
my+= get_symbol(&s->c, &s->block_state[128 + 32*(my_context + 16*!!ref)], 1); my+= get_symbol(&s->c, &s->block_state[128 + 32*(my_context + 16*!!ref)], 1);
} }
set_blocks(s, level, x, y, l, cb, cr, mx, my, ref, type); set_blocks(s, level, x, y, l, cb, cr, mx, my, ref, type);
}else{ }else{
decode_q_branch(s, level+1, 2*x+0, 2*y+0); if ((res = decode_q_branch(s, level+1, 2*x+0, 2*y+0)) < 0 ||
decode_q_branch(s, level+1, 2*x+1, 2*y+0); (res = decode_q_branch(s, level+1, 2*x+1, 2*y+0)) < 0 ||
decode_q_branch(s, level+1, 2*x+0, 2*y+1); (res = decode_q_branch(s, level+1, 2*x+0, 2*y+1)) < 0 ||
decode_q_branch(s, level+1, 2*x+1, 2*y+1); (res = decode_q_branch(s, level+1, 2*x+1, 2*y+1)) < 0)
return res;
} }
return 0;
} }
static void dequantize_slice_buffered(SnowContext *s, slice_buffer * sb, SubBand *b, IDWTELEM *src, int stride, int start_y, int end_y){ static void dequantize_slice_buffered(SnowContext *s, slice_buffer * sb, SubBand *b, IDWTELEM *src, int stride, int start_y, int end_y){
...@@ -354,16 +361,19 @@ static av_cold int decode_init(AVCodecContext *avctx) ...@@ -354,16 +361,19 @@ static av_cold int decode_init(AVCodecContext *avctx)
return 0; return 0;
} }
static void decode_blocks(SnowContext *s){ static int decode_blocks(SnowContext *s){
int x, y; int x, y;
int w= s->b_width; int w= s->b_width;
int h= s->b_height; int h= s->b_height;
int res;
for(y=0; y<h; y++){ for(y=0; y<h; y++){
for(x=0; x<w; x++){ for(x=0; x<w; x++){
decode_q_branch(s, 0, x, y); if ((res = decode_q_branch(s, 0, x, y)) < 0)
return res;
} }
} }
return 0;
} }
static int decode_frame(AVCodecContext *avctx, void *data, int *data_size, AVPacket *avpkt){ static int decode_frame(AVCodecContext *avctx, void *data, int *data_size, AVPacket *avpkt){
...@@ -374,6 +384,7 @@ static int decode_frame(AVCodecContext *avctx, void *data, int *data_size, AVPac ...@@ -374,6 +384,7 @@ static int decode_frame(AVCodecContext *avctx, void *data, int *data_size, AVPac
int bytes_read; int bytes_read;
AVFrame *picture = data; AVFrame *picture = data;
int level, orientation, plane_index; int level, orientation, plane_index;
int res;
ff_init_range_decoder(c, buf, buf_size); ff_init_range_decoder(c, buf, buf_size);
ff_build_rac_states(c, 0.05*(1LL<<32), 256-8); ff_build_rac_states(c, 0.05*(1LL<<32), 256-8);
...@@ -402,7 +413,8 @@ static int decode_frame(AVCodecContext *avctx, void *data, int *data_size, AVPac ...@@ -402,7 +413,8 @@ static int decode_frame(AVCodecContext *avctx, void *data, int *data_size, AVPac
if(avctx->debug&FF_DEBUG_PICT_INFO) if(avctx->debug&FF_DEBUG_PICT_INFO)
av_log(avctx, AV_LOG_ERROR, "keyframe:%d qlog:%d\n", s->keyframe, s->qlog); av_log(avctx, AV_LOG_ERROR, "keyframe:%d qlog:%d\n", s->keyframe, s->qlog);
decode_blocks(s); if ((res = decode_blocks(s)) < 0)
return res;
for(plane_index=0; plane_index<3; plane_index++){ for(plane_index=0; plane_index<3; plane_index++){
Plane *p= &s->plane[plane_index]; Plane *p= &s->plane[plane_index];
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment