Fixed out of bound reads in stack variables

Out of bound reads in the following variables are fixed

scaling_mat_offset in ihevcd_iquant_itrans_recon_ctb()
ai1_offset_y, ai1_offset_cb and ai1_offset_cr in ihevcd_sao_shift_ctb()

These values were read but not used

b/32915871

Change-Id: Ib07e2ed1bdcc600700d4e9e5d970f6cc2164ab1b
This commit is contained in:
Harish Mahendrakar 2015-12-18 10:09:18 +05:30 • committed by Zach Jang
parent 063ce60457
commit 4def2dfabf
2 changed files with 9 additions and 6 deletions

View file

@ -567,9 +567,11 @@ WORD32 ihevcd_iquant_itrans_recon_ctb(process_ctxt_t *ps_proc)
/* Intra 32x32 Y */
/* Inter 32x32 Y */
/*************************************************************************/
WORD32 scaling_mat_offset[] =
/* Only first 20 entries are used. Array is extended to avoid out of bound
reads. Skip CUs (64x64) read this table, but don't really use the value */
static const WORD32 scaling_mat_offset[] =
{ 0, 16, 32, 48, 64, 80, 96, 160, 224, 288, 352, 416, 480, 736, 992,
1248, 1504, 1760, 2016, 3040 };
1248, 1504, 1760, 2016, 3040, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 };
PROFILE_DISABLE_IQ_IT_RECON_INTRA_PRED();

View file

@ -568,10 +568,11 @@ void ihevcd_sao_shift_ctb(sao_ctxt_t *ps_sao_ctxt)
UWORD8 *pu1_sao_src_top_left_luma_bot_left;
UWORD8 *au1_sao_src_top_left_chroma_bot_left;
UWORD8 *pu1_sao_src_top_left_chroma_bot_left;
WORD8 ai1_offset_y[5];
WORD8 ai1_offset_cb[5];
WORD8 ai1_offset_cr[5];
/* Only 5 values are used, but arrays are large
enough so that SIMD functions can read 64 bits at a time */
WORD8 ai1_offset_y[8];
WORD8 ai1_offset_cb[8];
WORD8 ai1_offset_cr[8];
WORD32 chroma_yuv420sp_vu = ps_sao_ctxt->is_chroma_yuv420sp_vu;
PROFILE_DISABLE_SAO();