Skip to content

fix off-by-one in avifGetExifTiffHeaderOffset scan bound - #3400

Merged
y-guyon merged 1 commit into
AOMediaCodec:mainfrom
Arawoof06:exif-tiff-header-offset-bound
Oct 2, 2026
Merged

y-guyon merged 1 commit into
AOMediaCodec:mainfrom
Arawoof06:exif-tiff-header-offset-bound

Conversation

@Arawoof06

Copy link
Copy Markdown
Contributor

avifGetExifTiffHeaderOffset scans the Exif payload for the TIFF header but bounds the loop with *offset + 4 < exifSize, which stops one byte early and never checks the final four-byte window, so a header located in the last four bytes of the payload is reported as missing even though reading it there is in bounds. Changing the comparison to <= examines that last position. Added a regression test with the little- and big-endian headers placed at the end of the buffer.

@y-guyon
y-guyon merged commit fa659d2 into AOMediaCodec:main Oct 2, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants