Skip to content

Reject image sequences with total sample size exceeding 16x file size - #3402

Open
17krishna8 wants to merge 1 commit into
AOMediaCodec:mainfrom
17krishna8:seq-sample-size-guard
Open

17krishna8 wants to merge 1 commit into
AOMediaCodec:mainfrom
17krishna8:seq-sample-size-guard

Conversation

@17krishna8

Copy link
Copy Markdown

Description

avifCodecDecodeInputFillFromSampleTable() materializes one avifDecodeSample per sample declared by the stsc/stsz/stco boxes, at parse time. Each sample is individually checked against the io sizeHint (offset + size <= sizeHint), but nothing bounds the sum of the sample sizes, and overlapping chunks are not rejected. A tiny crafted file can therefore declare a huge number of samples that all overlap at the same offset:

  • a 4 KiB file with 1000 stco entries at offset 0, samplesPerChunk = 2592 and allSamplesSize = 1 parses successfully with imageCount = 2 592 000 (the whole default imageCountLimit budget) and about 125 MiB of materialized samples, before any decoding happens. Nothing in the file is invalid per se: all per-sample checks pass because every sample is within the file.

This is the image-sequence counterpart of the iloc over-allocation issue (#3372, #3398): the still-image path bounds item data against the file size, but the track/sample-table path does not.

Change

avifCodecDecodeInputFillFromSampleTable() now sums the sample sizes while filling the decode input and rejects the file when the total exceeds 16x the sizeHint (returning AVIF_RESULT_NOT_IMPLEMENTED, mirroring the proposed iloc guard in #3398):

  • chunks are disjoint in a well-formed file, so the sum of the sample sizes is at most the file size there; 16x leaves a comfortable margin,
  • files streamed through a custom avifIO with no sizeHint are unaffected (the bound is disabled, as is the existing per-sample check),
  • the sum is also overflow-checked for completeness.

Test

New avifsampletabletest builds hand-crafted minimal avis files byte-by-byte (no test data needed):

  • SampleTableTest.OverlappingChunksExceedTotalSizeBudget — the file above fails at head (parse returns OK with imageCount = 2 592 000) and returns AVIF_RESULT_NOT_IMPLEMENTED with this change,
  • SampleTableTest.DisjointChunksParse — control: a well-formed sequence still parses with the right imageCount.

All existing sequence tests pass locally (avifanimationtest, avifkeyframetest, avifiostatstest, avifdecodetest).

Suggested changelog entry: Reject image sequences whose sample table declares more sample data than the file can hold.

avifCodecDecodeInputFillFromSampleTable() materializes one
avifDecodeSample per sample declared by the stsc/stsz/stco boxes. Each
sample is individually checked against the io sizeHint, but overlapping
chunks are not, so a tiny file declaring many chunks at the same offset
and the default imageCountLimit can materialize the whole budget of
samples: a 4 KiB file parses successfully with imageCount = 2 592 000
and about 125 MiB of samples, before any decoding.

Reject the sample table instead when the sum of the sample sizes
exceeds 16x the sizeHint, mirroring the equivalent iloc guard for
still images. Chunks are disjoint in a well-formed file, so the sum of
the sample sizes is at most the file size there; 16x leaves a
comfortable margin. Files streamed through a custom avifIO with no
sizeHint are unaffected.

The new avifsampletabletest builds hand-crafted minimal 'avis' files;
OverlappingChunksExceedTotalSizeBudget fails at head (parse returns OK
with imageCount = 2 592 000) and passes with this change.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant