Commit 356a391bf5 for ffmpeg

commit 356a391bf57df2fb80fd61f2821c8c83d15ce180
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Sun Oct 4 03:56:21 2026 +0200

    avcodec/sunrast: zero the rest of the raster the input ends in

    The RLE case was found during triage of the security report
    Yf3lKVRHj1Sr, the zeroing in the frame was added then as hardening

    Fixes: use of uninitialized memory
    Fixes: Yf3lKVRHj1Sr
    Regression since: ceb0dd9f1e
    Found-by: Adrian Junge (vurlo)

diff --git a/libavcodec/sunrast.c b/libavcodec/sunrast.c
index cc27838f5b..1cd51f4637 100644
--- a/libavcodec/sunrast.c
+++ b/libavcodec/sunrast.c
@@ -156,11 +156,11 @@ static int sunrast_decode_frame(AVCodecContext *avctx, AVFrame *p,
         stride = p->linesize[0];
     }

+    uint8_t *end = ptr + (ptrdiff_t)h * stride;
+    x = 0;
     if (type == RT_BYTE_ENCODED) {
         int value, run;
-        uint8_t *end = ptr + (ptrdiff_t)h * stride;

-        x = 0;
         while (ptr != end && buf < buf_end) {
             run = 1;
             if (buf_end - buf < 1) {
@@ -193,6 +193,8 @@ static int sunrast_decode_frame(AVCodecContext *avctx, AVFrame *p,
             buf += alen;
         }
     }
+    for (; ptr != end; ptr += stride, x = 0)
+        memset(ptr + x, 0, len - x);
     if (avctx->pix_fmt == AV_PIX_FMT_PAL8 && depth < 8) {
         uint8_t *ptr_free = ptr2;
         ptr = p->data[0];