Commit c0d308a9a6 for ffmpeg

commit c0d308a9a616f4abcc4e0a4d86f7de92ecdef9f6
Author: Michael Niedermayer <michael@niedermayer.cc>
Date:   Tue Oct 6 06:18:55 2026 +0200

    avcodec/flicvideo: byte swap the decoded pixels in big endian FLI_BRUN

    The swap read the packet at frame offsets instead of the decoded line,
    past the end of the packet for frames larger than it.

    That this reads past the packet was found during triage of the security
    report bQcit4JdHaHN.

    Fixes: out of array read
    Fixes: bQcit4JdHaHN
    Found-by: Joey Tang <fishjojo1@gmail.com>
    Out of array read Replicated through Modified FFmpeg with ASAN
    Segmentation fault Replicated through UnModified FFmpeg (s390x) with qemu-s390x

diff --git a/libavcodec/flicvideo.c b/libavcodec/flicvideo.c
index c678a4832f..b8157c0e51 100644
--- a/libavcodec/flicvideo.c
+++ b/libavcodec/flicvideo.c
@@ -881,7 +881,7 @@ static int flic_decode_frame_15_16BPP(AVCodecContext *avctx,
                 pixel_ptr = y_ptr;
                 pixel_countdown = s->avctx->width;
                 while (pixel_countdown > 0) {
-                    *((signed short*)(&pixels[pixel_ptr])) = AV_RL16(&buf[pixel_ptr]);
+                    *((signed short*)(&pixels[pixel_ptr])) = AV_RL16(&pixels[pixel_ptr]);
                     pixel_ptr += 2;
                     pixel_countdown--;
                 }