Signed-off-by: hdliu <dev03108@linx-info.com> (cherry picked from commit 17fcfecd9864d8df5b75cb8e3472fc78755a516c)
36 lines
1.3 KiB
Diff
36 lines
1.3 KiB
Diff
From 70769b2a619f9f9bff9cd46285c1626156095411 Mon Sep 17 00:00:00 2001
|
|
From: root <root@localhost.localdomain>
|
|
Date: Mon, 21 Apr 2025 12:26:06 +0800
|
|
Subject: [PATCH] prevent out-of-buffer access in phase_one_correct()
|
|
|
|
Signed-off-by: hdliu <hdliu@linx-info.com>
|
|
---
|
|
src/decoders/load_mfbacks.cpp | 4 ++--
|
|
1 file changed, 2 insertions(+), 2 deletions(-)
|
|
|
|
diff --git a/src/decoders/load_mfbacks.cpp b/src/decoders/load_mfbacks.cpp
|
|
index 9d7c051..a8f2c6d 100644
|
|
--- a/src/decoders/load_mfbacks.cpp
|
|
+++ b/src/decoders/load_mfbacks.cpp
|
|
@@ -211,7 +211,7 @@ int LibRaw::phase_one_correct()
|
|
off_412 = ftell(ifp) - 38;
|
|
}
|
|
}
|
|
- else if (tag == 0x041f && !qlin_applied)
|
|
+ else if (tag == 0x041f && !qlin_applied && ph1.split_col > 0 && ph1.split_col < raw_width && ph1.split_row > 0 && ph1.split_row < raw_height)
|
|
{ /* Quadrant linearization */
|
|
ushort lc[2][2][16], ref[16];
|
|
int qr, qc;
|
|
@@ -288,7 +288,7 @@ int LibRaw::phase_one_correct()
|
|
}
|
|
qmult_applied = 1;
|
|
}
|
|
- else if (tag == 0x0431 && !qmult_applied)
|
|
+ else if (tag == 0x0431 && !qmult_applied && ph1.split_col > 0 && ph1.split_col < raw_width && ph1.split_row > 0 && ph1.split_row < raw_height)
|
|
{ /* Quadrant combined */
|
|
ushort lc[2][2][7], ref[7];
|
|
int qr, qc;
|
|
--
|
|
2.33.0
|
|
|