avfilter/v360: reject out-of-range dimensions

Fixes: integer overflow

Found-by: Kery (Qi Kery <qikeyu2001@outlook.com>)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
Michael Niedermayer
2026-06-08 02:30:38 +02:00
committed by michaelni
parent 19e377b4b9
commit fd6b3fa423
+38 -2
View File
@@ -4295,6 +4295,20 @@ static int v360_slice(AVFilterContext *ctx, void *arg, int jobnr, int nb_jobs)
return 0;
}
static int get_output_dimension(AVFilterContext *ctx, const char *name,
float val, int *dim)
{
if (!isfinite(val) || val < 1.f || val > INT16_MAX) {
av_log(ctx, AV_LOG_ERROR,
"Output %s %g is outside the allowed range [1, %d].\n",
name, val, INT16_MAX);
return AVERROR(EINVAL);
}
*dim = lrintf(val);
return 0;
}
static int config_output(AVFilterLink *outlink)
{
AVFilterContext *ctx = outlink->src;
@@ -4466,6 +4480,15 @@ static int config_output(AVFilterLink *outlink)
if (s->in_transpose)
FFSWAP(int, s->in_width, s->in_height);
// The remap code stores input coordinates in int16_t
if (s->in_width < 1 || s->in_width > INT16_MAX ||
s->in_height < 1 || s->in_height > INT16_MAX) {
av_log(ctx, AV_LOG_ERROR,
"Input dimensions %dx%d are outside the allowed range [1, %d].\n",
s->in_width, s->in_height, INT16_MAX);
return AVERROR(EINVAL);
}
switch (s->in) {
case EQUIRECTANGULAR:
s->in_transform = xyz_to_equirect;
@@ -4783,11 +4806,17 @@ static int config_output(AVFilterLink *outlink)
if (s->width > 0 && s->height <= 0 && s->h_fov > 0.f && s->v_fov > 0.f &&
s->out == FLAT && s->d_fov == 0.f) {
w = s->width;
h = w / tanf(s->h_fov * M_PI / 360.f) * tanf(s->v_fov * M_PI / 360.f);
err = get_output_dimension(ctx, "height",
w / tanf(s->h_fov * M_PI / 360.f) * tanf(s->v_fov * M_PI / 360.f), &h);
if (err < 0)
return err;
} else if (s->width <= 0 && s->height > 0 && s->h_fov > 0.f && s->v_fov > 0.f &&
s->out == FLAT && s->d_fov == 0.f) {
h = s->height;
w = h / tanf(s->v_fov * M_PI / 360.f) * tanf(s->h_fov * M_PI / 360.f);
err = get_output_dimension(ctx, "width",
h / tanf(s->v_fov * M_PI / 360.f) * tanf(s->h_fov * M_PI / 360.f), &w);
if (err < 0)
return err;
} else if (s->width > 0 && s->height > 0) {
w = s->width;
h = s->height;
@@ -4802,6 +4831,13 @@ static int config_output(AVFilterLink *outlink)
FFSWAP(int, w, h);
}
if (w < 1 || w > INT16_MAX || h < 1 || h > INT16_MAX) {
av_log(ctx, AV_LOG_ERROR,
"Output dimensions %dx%d are outside the allowed range [1, %d].\n",
w, h, INT16_MAX);
return AVERROR(EINVAL);
}
s->width = w;
s->height = h;