Commit edad2d0daf for ffmpeg
commit edad2d0dafcf44fa315eab716fd0183ce808053b
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Fri Oct 2 16:09:42 2026 +0200
avcodec/g2meet: check the palette index of Kempf tile pixels
Fixes: use of uninitialized memory
Fixes: Vz1pe7DZm4HV
Found-by: Adrian Junge (vurlo)
diff --git a/libavcodec/g2meet.c b/libavcodec/g2meet.c
index 1aeb128c4f..9fada99344 100644
--- a/libavcodec/g2meet.c
+++ b/libavcodec/g2meet.c
@@ -1038,6 +1038,8 @@ static int kempf_restore_buf(const uint8_t *src, int len,
continue;
for (i = 0; i < width; i++) {
col = get_bits(&gb, nb);
+ if (col >= npal)
+ return AVERROR_INVALIDDATA;
if (col != tidx)
memcpy(dst + i * 3, pal + col * 3, 3);
else
@@ -1114,11 +1116,9 @@ static int kempf_decode_tile(G2MContext *c, int tile_x, int tile_y,
return AVERROR_INVALIDDATA;
src += zsize;
- if (sub_type == 2) {
- kempf_restore_buf(c->kempf_buf, dlen, dst, c->framebuf_stride,
- NULL, 0, width, height, pal, npal, tidx);
- return 0;
- }
+ if (sub_type == 2)
+ return kempf_restore_buf(c->kempf_buf, dlen, dst, c->framebuf_stride,
+ NULL, 0, width, height, pal, npal, tidx);
nblocks = *src++ + 1;
cblocks = 0;
@@ -1151,11 +1151,9 @@ static int kempf_decode_tile(G2MContext *c, int tile_x, int tile_y,
c->jpeg_tile, c->tile_stride,
c->kempf_flags, bstride, nblocks * 4, 0);
- kempf_restore_buf(c->kempf_buf, dlen, dst, c->framebuf_stride,
- c->jpeg_tile, c->tile_stride,
- width, height, pal, npal, tidx);
-
- return 0;
+ return kempf_restore_buf(c->kempf_buf, dlen, dst, c->framebuf_stride,
+ c->jpeg_tile, c->tile_stride,
+ width, height, pal, npal, tidx);
}
static int g2m_init_buffers(G2MContext *c)