Commit c0d308a9a6 for ffmpeg
commit c0d308a9a616f4abcc4e0a4d86f7de92ecdef9f6
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Tue Oct 6 06:18:55 2026 +0200
avcodec/flicvideo: byte swap the decoded pixels in big endian FLI_BRUN
The swap read the packet at frame offsets instead of the decoded line,
past the end of the packet for frames larger than it.
That this reads past the packet was found during triage of the security
report bQcit4JdHaHN.
Fixes: out of array read
Fixes: bQcit4JdHaHN
Found-by: Joey Tang <fishjojo1@gmail.com>
Out of array read Replicated through Modified FFmpeg with ASAN
Segmentation fault Replicated through UnModified FFmpeg (s390x) with qemu-s390x
diff --git a/libavcodec/flicvideo.c b/libavcodec/flicvideo.c
index c678a4832f..b8157c0e51 100644
--- a/libavcodec/flicvideo.c
+++ b/libavcodec/flicvideo.c
@@ -881,7 +881,7 @@ static int flic_decode_frame_15_16BPP(AVCodecContext *avctx,
pixel_ptr = y_ptr;
pixel_countdown = s->avctx->width;
while (pixel_countdown > 0) {
- *((signed short*)(&pixels[pixel_ptr])) = AV_RL16(&buf[pixel_ptr]);
+ *((signed short*)(&pixels[pixel_ptr])) = AV_RL16(&pixels[pixel_ptr]);
pixel_ptr += 2;
pixel_countdown--;
}