* gnu/packages/patches/libvpx-use-after-free-in-postproc.patch: New file. * gnu/local.mk (dist_patch_DATA): Add it. * gnu/packages/video.scm (libvpx)[source]: Add patch.
		
			
				
	
	
		
			34 lines
		
	
	
	
		
			1.2 KiB
		
	
	
	
		
			Diff
		
	
	
	
	
	
			
		
		
	
	
			34 lines
		
	
	
	
		
			1.2 KiB
		
	
	
	
		
			Diff
		
	
	
	
	
	
| From 52add5896661d186dec284ed646a4b33b607d2c7 Mon Sep 17 00:00:00 2001
 | |
| From: Jerome Jiang <jianj@google.com>
 | |
| Date: Wed, 23 May 2018 15:43:00 -0700
 | |
| Subject: [PATCH] VP8: Fix use-after-free in postproc.
 | |
| 
 | |
| The pointer in vp8 postproc refers to show_frame_mi which is only
 | |
| updated on show frame. However, when there is a no-show frame which also
 | |
| changes the size (thus new frame buffers allocated), show_frame_mi is
 | |
| not updated with new frame buffer memory.
 | |
| 
 | |
| Change the pointer in postproc to mi which is always updated.
 | |
| 
 | |
| Bug: 842265
 | |
| Change-Id: I33874f2112b39f74562cba528432b5f239e6a7bd
 | |
| ---
 | |
|  vp8/common/postproc.c | 2 +-
 | |
|  1 file changed, 1 insertion(+), 1 deletion(-)
 | |
| 
 | |
| diff --git a/vp8/common/postproc.c b/vp8/common/postproc.c
 | |
| index d67ee8a57..8c292d616 100644
 | |
| --- a/vp8/common/postproc.c
 | |
| +++ b/vp8/common/postproc.c
 | |
| @@ -65,7 +65,7 @@ void vp8_deblock(VP8_COMMON *cm, YV12_BUFFER_CONFIG *source,
 | |
|    double level = 6.0e-05 * q * q * q - .0067 * q * q + .306 * q + .0065;
 | |
|    int ppl = (int)(level + .5);
 | |
|  
 | |
| -  const MODE_INFO *mode_info_context = cm->show_frame_mi;
 | |
| +  const MODE_INFO *mode_info_context = cm->mi;
 | |
|    int mbr, mbc;
 | |
|  
 | |
|    /* The pixel thresholds are adjusted according to if or not the macroblock
 | |
| -- 
 | |
| 2.19.0
 | |
| 
 |