Skip to content

vpx_image: reject zero dimensions in alloc/wrap/set_rect - #11

Open
kalt2212 wants to merge 1 commit into
webmproject:mainfrom
kalt2212:patch/vpx-img-flip-zero-dim-guard
Open

kalt2212 wants to merge 1 commit into
webmproject:mainfrom
kalt2212:patch/vpx-img-flip-zero-dim-guard

Conversation

@kalt2212

Copy link
Copy Markdown

vpx_img_flip() computes (d_h - 1) * stride to relocate the
plane pointers. d_h is unsigned, so flipping an image with
d_h == 0 underflows to UINT_MAX and produces a wild plane
pointer ~64 GiB away from the buffer.

d_h == 0 is reachable through the public API: vpx_img_wrap()
accepted a zero height and vpx_img_set_rect() accepted a
zero-area viewport, neither of which can ever be encoded
(the encoders require the image size to match the configured
size, which is always >= 1).

This patch rejects zero widths/heights in img_alloc_helper()
(covers both vpx_img_alloc() and vpx_img_wrap()) and
zero-area viewports in vpx_img_set_rect().

PoC (before the fix): wrapping a zero-height image and calling
vpx_img_flip() displaced the plane pointers by 68719476720
bytes (~64 GiB). After the fix the calls return NULL / fail
gracefully. Reproduced under ASan+UBSan; the change passes
the vpx_image_test suite (12/12).

vpx_img_flip() computes (d_h - 1) * stride to relocate the plane
pointers. d_h is unsigned, so flipping an image with d_h == 0
underflows to UINT_MAX and produces a wild plane pointer ~64 GiB
away from the buffer. d_h == 0 is reachable through the public API:
vpx_img_wrap() accepted a zero height and vpx_img_set_rect() accepted
a zero-area viewport, neither of which can ever be encoded (the
encoders require the image size to match the configured size, which
is always >= 1).

Reject zero widths/heights in img_alloc_helper() (covers both
vpx_img_alloc() and vpx_img_wrap()) and zero-area viewports in
vpx_img_set_rect().
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant