fixes oob read
This commit is contained in:
@@ -93,18 +93,18 @@ size_t FSE_readNCount (short* normalizedCounter, unsigned* maxSVPtr, unsigned* t
|
|||||||
if (previous0) {
|
if (previous0) {
|
||||||
unsigned n0 = charnum;
|
unsigned n0 = charnum;
|
||||||
while ((bitStream & 0xFFFF) == 0xFFFF) {
|
while ((bitStream & 0xFFFF) == 0xFFFF) {
|
||||||
n0+=24;
|
n0 += 24;
|
||||||
if (ip < iend-5) {
|
if (ip < iend-5) {
|
||||||
ip+=2;
|
ip += 2;
|
||||||
bitStream = MEM_readLE32(ip) >> bitCount;
|
bitStream = MEM_readLE32(ip) >> bitCount;
|
||||||
} else {
|
} else {
|
||||||
bitStream >>= 16;
|
bitStream >>= 16;
|
||||||
bitCount+=16;
|
bitCount += 16;
|
||||||
} }
|
} }
|
||||||
while ((bitStream & 3) == 3) {
|
while ((bitStream & 3) == 3) {
|
||||||
n0+=3;
|
n0 += 3;
|
||||||
bitStream>>=2;
|
bitStream >>= 2;
|
||||||
bitCount+=2;
|
bitCount += 2;
|
||||||
}
|
}
|
||||||
n0 += bitStream & 3;
|
n0 += bitStream & 3;
|
||||||
bitCount += 2;
|
bitCount += 2;
|
||||||
@@ -148,6 +148,7 @@ size_t FSE_readNCount (short* normalizedCounter, unsigned* maxSVPtr, unsigned* t
|
|||||||
bitStream = MEM_readLE32(ip) >> (bitCount & 31);
|
bitStream = MEM_readLE32(ip) >> (bitCount & 31);
|
||||||
} } /* while ((remaining>1) & (charnum<=*maxSVPtr)) */
|
} } /* while ((remaining>1) & (charnum<=*maxSVPtr)) */
|
||||||
if (remaining != 1) return ERROR(corruption_detected);
|
if (remaining != 1) return ERROR(corruption_detected);
|
||||||
|
if (bitCount > 32) return ERROR(corruption_detected);
|
||||||
*maxSVPtr = charnum-1;
|
*maxSVPtr = charnum-1;
|
||||||
|
|
||||||
ip += (bitCount+7)>>3;
|
ip += (bitCount+7)>>3;
|
||||||
|
|||||||
@@ -536,14 +536,12 @@ size_t ZSTD_decodeSeqHeaders(int* nbSeqPtr,
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* FSE table descriptors */
|
/* FSE table descriptors */
|
||||||
|
if (ip+4 > iend) return ERROR(srcSize_wrong); /* minimum possible size */
|
||||||
{ symbolEncodingType_e const LLtype = (symbolEncodingType_e)(*ip >> 6);
|
{ symbolEncodingType_e const LLtype = (symbolEncodingType_e)(*ip >> 6);
|
||||||
symbolEncodingType_e const OFtype = (symbolEncodingType_e)((*ip >> 4) & 3);
|
symbolEncodingType_e const OFtype = (symbolEncodingType_e)((*ip >> 4) & 3);
|
||||||
symbolEncodingType_e const MLtype = (symbolEncodingType_e)((*ip >> 2) & 3);
|
symbolEncodingType_e const MLtype = (symbolEncodingType_e)((*ip >> 2) & 3);
|
||||||
ip++;
|
ip++;
|
||||||
|
|
||||||
/* check */
|
|
||||||
if (ip > iend-3) return ERROR(srcSize_wrong); /* min : all 3 are "raw", hence no header, but at least xxLog bits per type */
|
|
||||||
|
|
||||||
/* Build DTables */
|
/* Build DTables */
|
||||||
{ size_t const llhSize = ZSTD_buildSeqTable(DTableLL, LLtype, MaxLL, LLFSELog, ip, iend-ip, LL_defaultNorm, LL_defaultNormLog, flagRepeatTable);
|
{ size_t const llhSize = ZSTD_buildSeqTable(DTableLL, LLtype, MaxLL, LLFSELog, ip, iend-ip, LL_defaultNorm, LL_defaultNormLog, flagRepeatTable);
|
||||||
if (ZSTD_isError(llhSize)) return ERROR(corruption_detected);
|
if (ZSTD_isError(llhSize)) return ERROR(corruption_detected);
|
||||||
|
|||||||
Reference in New Issue
Block a user