SplashDecodeGif() uses gif->SBackGroundColor as an index into colorMap->Colors when handling GIF_DISPOSE_BACKGND.
The background colour index is read from the GIF Logical Screen Descriptor and may contain a value from 0 to 255. The value is not validated against colorMap->ColorCount before indexing the colour table. A malformed GIF with a small colour table and an out-of-range SBackGroundColor can therefore cause an out-of-bounds heap read. For example, a GIF with a colour table containing two entries and SBackGroundColor = 255 causes colorMap->Colors[255] to be accessed. The resulting colour value is subsequently used to fill the disposed frame background, exposing adjacent heap contents in the rendered splash image. Add a bounds check ensuring SBackGroundColor is within ColorCount before indexing the colour table. --------- - [x] I confirm that I make this contribution in accordance with the [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai). ------------- Commit messages: - 8393264: SplashDecodeGif may read past colour table Changes: https://git.openjdk.org/jdk/pull/33145/files Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=33145&range=00 Issue: https://bugs.openjdk.org/browse/JDK-8393264 Stats: 2 lines in 1 file changed: 1 ins; 0 del; 1 mod Patch: https://git.openjdk.org/jdk/pull/33145.diff Fetch: git fetch https://git.openjdk.org/jdk.git pull/33145/head:pull/33145 PR: https://git.openjdk.org/jdk/pull/33145
