From 447d98b07235c04437e7d3836fc97195a503fe3d Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Thu, 18 Sep 2025 17:32:46 +0200 Subject: [PATCH] avcodec/exr: check ac_size Fixes: out of array read Fixes: dwa_uncompress.py.crash.exr The code will read from the ac data even if ac_size is 0, thus that case is not implemented and we ask for a sample and error out cleanly Found-by: Google Big Sleep Signed-off-by: Michael Niedermayer (cherry picked from commit 8e078826da6f2a1dffa25162121b43b272f5e5fa) Signed-off-by: Michael Niedermayer --- libavcodec/exr.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/libavcodec/exr.c b/libavcodec/exr.c index d277eb7858..85c925fb66 100644 --- a/libavcodec/exr.c +++ b/libavcodec/exr.c @@ -1023,6 +1023,11 @@ static int dwa_uncompress(EXRContext *s, const uint8_t *src, int compressed_size ) return AVERROR_INVALIDDATA; + if (ac_size <= 0) { + avpriv_request_sample(s->avctx, "Zero ac_size"); + return AVERROR_INVALIDDATA; + } + if ((uint64_t)rle_raw_size > INT_MAX) { avpriv_request_sample(s->avctx, "Too big rle_raw_size"); return AVERROR_INVALIDDATA;