Commit 356a391bf5 for ffmpeg
commit 356a391bf57df2fb80fd61f2821c8c83d15ce180
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Sun Oct 4 03:56:21 2026 +0200
avcodec/sunrast: zero the rest of the raster the input ends in
The RLE case was found during triage of the security report
Yf3lKVRHj1Sr, the zeroing in the frame was added then as hardening
Fixes: use of uninitialized memory
Fixes: Yf3lKVRHj1Sr
Regression since: ceb0dd9f1e
Found-by: Adrian Junge (vurlo)
diff --git a/libavcodec/sunrast.c b/libavcodec/sunrast.c
index cc27838f5b..1cd51f4637 100644
--- a/libavcodec/sunrast.c
+++ b/libavcodec/sunrast.c
@@ -156,11 +156,11 @@ static int sunrast_decode_frame(AVCodecContext *avctx, AVFrame *p,
stride = p->linesize[0];
}
+ uint8_t *end = ptr + (ptrdiff_t)h * stride;
+ x = 0;
if (type == RT_BYTE_ENCODED) {
int value, run;
- uint8_t *end = ptr + (ptrdiff_t)h * stride;
- x = 0;
while (ptr != end && buf < buf_end) {
run = 1;
if (buf_end - buf < 1) {
@@ -193,6 +193,8 @@ static int sunrast_decode_frame(AVCodecContext *avctx, AVFrame *p,
buf += alen;
}
}
+ for (; ptr != end; ptr += stride, x = 0)
+ memset(ptr + x, 0, len - x);
if (avctx->pix_fmt == AV_PIX_FMT_PAL8 && depth < 8) {
uint8_t *ptr_free = ptr2;
ptr = p->data[0];