Fixes very long but finite loop
Fixes: asan_heap-oob_107866c_42_041.drc
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
(cherry picked from commit 5145d22b88b9835db81c4d286b931a78e08ab76a)
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
... | ... |
@@ -990,8 +990,8 @@ static int dirac_unpack_idwt_params(DiracContext *s) |
990 | 990 |
/* Codeblock parameters (core syntax only) */ |
991 | 991 |
if (get_bits1(gb)) { |
992 | 992 |
for (i = 0; i <= s->wavelet_depth; i++) { |
993 |
- CHECKEDREAD(s->codeblock[i].width , tmp < 1, "codeblock width invalid\n") |
|
994 |
- CHECKEDREAD(s->codeblock[i].height, tmp < 1, "codeblock height invalid\n") |
|
993 |
+ CHECKEDREAD(s->codeblock[i].width , tmp < 1 || tmp > (s->avctx->width >>s->wavelet_depth-i), "codeblock width invalid\n") |
|
994 |
+ CHECKEDREAD(s->codeblock[i].height, tmp < 1 || tmp > (s->avctx->height>>s->wavelet_depth-i), "codeblock height invalid\n") |
|
995 | 995 |
} |
996 | 996 |
|
997 | 997 |
CHECKEDREAD(s->codeblock_mode, tmp > 1, "unknown codeblock mode\n") |