swscale: enforce a minimum filtersize.
At very small dimensions, this calculation could lead to zero-sized
filters, which leads to uninitialized output, zero-sized allocations,
loop overflows in SIMD that uses do{..}while(i++<filtersize); instead
of for(i=0;i<filtersize;i++){..} and several other similar failures.
Therefore, require a minimum filtersize of 1.
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
CC: libav-stable@libav.org
(cherry picked from commit dae2ce361a)
Signed-off-by: Anton Khirnov <anton@khirnov.net>
Signed-off-by: Reinhard Tartler <siretart@tauware.de>
This commit is contained in:
committed by
Reinhard Tartler
parent
fd3af2950a
commit
ce99c1bfb5
@@ -289,7 +289,7 @@ static int initFilter(int16_t **outFilter, int16_t **filterPos, int *outFilterSi
|
|||||||
if (xInc <= 1<<16) filterSize= 1 + sizeFactor; // upscale
|
if (xInc <= 1<<16) filterSize= 1 + sizeFactor; // upscale
|
||||||
else filterSize= 1 + (sizeFactor*srcW + dstW - 1)/ dstW;
|
else filterSize= 1 + (sizeFactor*srcW + dstW - 1)/ dstW;
|
||||||
|
|
||||||
if (filterSize > srcW-2) filterSize=srcW-2;
|
filterSize = av_clip(filterSize, 1, srcW - 2);
|
||||||
|
|
||||||
FF_ALLOC_OR_GOTO(NULL, filter, dstW*sizeof(*filter)*filterSize, fail);
|
FF_ALLOC_OR_GOTO(NULL, filter, dstW*sizeof(*filter)*filterSize, fail);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user