PR #22759 opened by joaonevess
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22759
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22759.patch

The w variable counts pixels, not bytes. The non-RLE path correctly
uses w-- (one pixel = 4 bytes), but the RLE path uses w -= 4, causing
the loop to terminate after roughly 1/4 of the expected pixels.

The w -= 4 was introduced in 14e99cb472 which moved the decrement
inside the loop to fix an OOB write (clusterfuzz-5423041009549312).
The move was correct, but the decrement value should have been 1 to
match the non-RLE path.

Signed-off-by: João Neves <[email protected]>


From 1b25624f9c70fc11abc5b57e1bf60187aad5f723 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Jo=C3=A3o=20Neves?= <[email protected]>
Date: Wed, 8 Apr 2026 13:55:37 -0700
Subject: [PATCH] avcodec/hdrdec: fix pixel count decrement in RLE decompress
 loop
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

The w variable counts pixels, not bytes. The non-RLE path correctly
uses w-- (one pixel = 4 bytes), but the RLE path uses w -= 4, causing
the loop to terminate after roughly 1/4 of the expected pixels.

The w -= 4 was introduced in 14e99cb472 which moved the decrement
inside the loop to fix an OOB write (clusterfuzz-5423041009549312).
The move was correct, but the decrement value should have been 1 to
match the non-RLE path.

Signed-off-by: João Neves <[email protected]>
---
 libavcodec/hdrdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavcodec/hdrdec.c b/libavcodec/hdrdec.c
index cffa7570db..1a6935ff75 100644
--- a/libavcodec/hdrdec.c
+++ b/libavcodec/hdrdec.c
@@ -72,7 +72,7 @@ static int decompress(uint8_t *scanline, int w, 
GetByteContext *gb, const uint8_
             for (int i = run << rshift; i > 0 && w > 0 && scanline >= start + 
4; i--) {
                 memcpy(scanline, scanline - 4, 4);
                 scanline += 4;
-                w -= 4;
+                w--;
             }
             rshift += 8;
             if (rshift > 16)
-- 
2.52.0

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to