From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTP id 94A0E4B99D for ; Tue, 2 Jul 2024 18:38:51 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 2DADE68D964; Tue, 2 Jul 2024 21:38:49 +0300 (EEST) Received: from mail-ed1-f41.google.com (mail-ed1-f41.google.com [209.85.208.41]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 048C768D88F for ; Tue, 2 Jul 2024 21:38:43 +0300 (EEST) Received: by mail-ed1-f41.google.com with SMTP id 4fb4d7f45d1cf-57cbc66a0a6so2978869a12.1 for ; Tue, 02 Jul 2024 11:38:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1719945522; x=1720550322; darn=ffmpeg.org; h=subject:date:from:to:message-id:from:to:cc:subject:date:message-id :reply-to; bh=jzS1NR6oXJzpJnbaCaEhQklTrP8E/WIRkFmzVLE1qeU=; b=OCU6jZ1ytmTpbjwjXjyWCtEMBEMM0AcF8UDPJkCWRZI1c/l4+X9suQIEpSKaoOuzkv hwEJWoUsv9jNtzTzL6S4+/Q016a+VrDqX5x/D2c14nm0kEt//ogvE+cJxeH1NVu6srx1 Rsky53ENxZKtCjqjIj+3odTTmuatLby8LkQRR4txFUsapDZHdowXqfXXEWWob9qCTs3W a40RfXWCQVrJl3QWpwFgGDYCb81SC5l8pHs+cVSsNFbNtBkuWPyQ+YP3txCbeI4PMG9b /IxyJkdGx/cn+wT3u+jJ7WyW9GO83WjKi+2jK2m4NBnxm6vmXJRdizux0Wivrc8bZQZO yoag== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1719945522; x=1720550322; h=subject:date:from:to:message-id:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=jzS1NR6oXJzpJnbaCaEhQklTrP8E/WIRkFmzVLE1qeU=; b=hbC33YSWeBKXHQKCIGMlv99rDwPDj4DA+HWRQ4GQKod4Tt2YMCvKMOLTfyKhy8zryU HQclo+EFu+Np835FUeQ5DkeQt5pEW+DNiUWSgA1MR9W5n4jfRFDp8+DNRbnlfOQqTlOM N9UsenxbjEZT98hYvcGWJT2Z7BZYtWWvJhs+cXkKK9hqHT0fF+zj8inxvcpVuaWR/uGa JwdFJNnf40GG5fkBxhPxH876xOt/BXACYN6u1rgwlojAGDJG0r196G//xqCtbbnVYA2v fSDGOwnA6s0DQrFsLhPY1jUQ1K41Nb1UblvsaxnlbfdRDntkx8QC6HjYUNchNqWaIZGf ZUiw== X-Gm-Message-State: AOJu0YxECXYGf4L9bHgc8mhsbk2JwhHtsR9Oq1w8nzWpt8UwxebHkOZ7 FLOYeDZbNygNrP1IBhsDp8/OuoUq+EpCe4kHA2XaBe04Wym8iTY1urs2Hw== X-Google-Smtp-Source: AGHT+IFNEUaQJyxgotrC4iP1NACiaQef2dtxCyrqNC9QZtV/COiJIZYl4xbzs+yEvirOCSofBwlEMg== X-Received: by 2002:a05:6402:3550:b0:58c:77b4:404b with SMTP id 4fb4d7f45d1cf-58c77b441e2mr344652a12.15.1719945522164; Tue, 02 Jul 2024 11:38:42 -0700 (PDT) Received: from localhost (p200300cccf0d6b0015dc1b9b6d5e601e.dip0.t-ipconnect.de. [2003:cc:cf0d:6b00:15dc:1b9b:6d5e:601e]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-58b43df9efdsm1305433a12.57.2024.07.02.11.38.41 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 02 Jul 2024 11:38:41 -0700 (PDT) Message-Id: To: From: "Marvin Scholz" Date: Tue, 2 Jul 2024 20:38:00 +0200 Subject: [FFmpeg-devel] [PATCH] lavfi/perlin: Fix out of bounds stack buffer write X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Archived-At: List-Archive: List-Post: An incorrect calculation in ff_perlin_init causes a write to the stack array at index 256, which is out of bounds. Fixes: CID1608711 --- libavfilter/perlin.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavfilter/perlin.c b/libavfilter/perlin.c index 09bae7ad33..ffad8c1e4e 100644 --- a/libavfilter/perlin.c +++ b/libavfilter/perlin.c @@ -129,7 +129,7 @@ int ff_perlin_init(FFPerlin *perlin, double period, int octaves, double persiste for (i = 0; i < 256; i++) { unsigned int random_idx = av_lfg_get(&lfg) % (256-i); uint8_t random_val = random_permutations[random_idx]; - random_permutations[random_idx] = random_permutations[256-i]; + random_permutations[random_idx] = random_permutations[255-i]; perlin->permutations[i] = perlin->permutations[i+256] = random_val; } base-commit: e783e45e29e78616debba7f6d1fe6e54dc336496 -- 2.39.3 (Apple Git-146) _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".