Commit 50d206a75b for ffmpeg
commit 50d206a75b5e60261d71b25657ae04891eb60290
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Sun Sep 13 02:33:31 2026 +0200
avcodec/flashsv: reject blocks whose inflate output is shorter than the block
Fixes: use of uninitialized memory
Fixes: poc.flv
Fixes: XQjkQVM5MO3V
Found-by: Umar Pathan (Umar0x)
diff --git a/libavcodec/flashsv.c b/libavcodec/flashsv.c
index 5a88cc5077..85540ed0d8 100644
--- a/libavcodec/flashsv.c
+++ b/libavcodec/flashsv.c
@@ -227,11 +227,7 @@ static int flashsv_decode_block(AVCodecContext *avctx, const AVPacket *avpkt,
if (ret == Z_DATA_ERROR) {
av_log(avctx, AV_LOG_ERROR, "Zlib resync occurred\n");
inflateSync(zstream);
- ret = inflate(zstream, Z_FINISH);
- }
-
- if (ret != Z_OK && ret != Z_STREAM_END) {
- //return -1;
+ inflate(zstream, Z_FINISH);
}
if (s->is_keyframe) {
@@ -242,6 +238,13 @@ static int flashsv_decode_block(AVCodecContext *avctx, const AVPacket *avpkt,
y_pos += s->diff_start;
if (!s->color_depth) {
+ int inflated = s->block_size * 3 - zstream->avail_out;
+
+ if (inflated < width * 3 * s->diff_height) {
+ av_log(avctx, AV_LOG_ERROR, "Inflated %d bytes, but %d are needed\n",
+ inflated, width * 3 * s->diff_height);
+ return AVERROR_INVALIDDATA;
+ }
/* Flash Screen Video stores the image upside down, so copy
* lines to destination in reverse order. */
for (k = 1; k <= s->diff_height; k++) {