Skip to content

Reject iloc with total item size exceeding 16x file size - #3398

Open
littlepig12345 wants to merge 1 commit into
AOMediaCodec:mainfrom
littlepig12345:fix-iloc-total-item-size
Open

littlepig12345 wants to merge 1 commit into
AOMediaCodec:mainfrom
littlepig12345:fix-iloc-total-item-size

Conversation

@littlepig12345

Copy link
Copy Markdown

avifDecoderParse() trusts the sum of item sizes declared in iloc. Multiple items can point at the same extent, so N items pointing at the same L-byte region cause N * L bytes to be allocated. A small file can therefore trigger a disproportionate allocation.

Test results:

Before the patch:

  • Peak WorkingSet: ~8015 MB
  • Elapsed: ~4.3 s
  • Result: "Out of memory"

After the patch:

  • Peak WorkingSet: ~19.7 MB
  • Elapsed: ~0.2 s
  • Result: "Not implemented" (total item size exceeds 16x file size; overlapping extents are not supported)

The check compares the total declared item size against the file size, regardless of how the amplification is constructed.

Overlapping extents are allowed by ISO/IEC 14496-12 but are not supported by libavif for allocation purposes, so the check returns AVIF_RESULT_NOT_IMPLEMENTED.

This follows up on the overlapping extents case mentioned by @y-guyon in #3375.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant