Bug Summary

File:root/firefox-clang/media/libjpeg/src/jdicc.c
Warning:line 89, column 17
Dereference of null pointer (loaded from variable 'icc_data_len')

Annotated Source Code

Press '?' to see keyboard shortcuts

clang -cc1 -cc1 -triple x86_64-pc-linux-gnu -O2 -analyze -disable-free -clear-ast-before-backend -disable-llvm-verifier -discard-value-names -main-file-name jdicc.c -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -analyzer-config-compatibility-mode=true -mrelocation-model pic -pic-level 2 -fhalf-no-semantic-interposition -mframe-pointer=all -relaxed-aliasing -ffp-contract=off -fno-rounding-math -mconstructor-aliases -funwind-tables=2 -target-cpu x86-64 -tune-cpu generic -debugger-tuning=gdb -fdebug-compilation-dir=/root/firefox-clang/obj-x86_64-pc-linux-gnu/media/libjpeg -fcoverage-compilation-dir=/root/firefox-clang/obj-x86_64-pc-linux-gnu/media/libjpeg -resource-dir /usr/lib/llvm-23/lib/clang/23 -include /root/firefox-clang/config/gcc_hidden.h -include /root/firefox-clang/obj-x86_64-pc-linux-gnu/mozilla-config.h -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/system_wrappers -U _FORTIFY_SOURCE -D _FORTIFY_SOURCE=2 -D DEBUG=1 -D MOZ_WITH_SIMD=1 -D MOZ_HAS_MOZGLUE -D MOZILLA_INTERNAL_API -D IMPL_LIBXUL -D MOZ_SUPPORT_LEAKCHECKING -D STATIC_EXPORTABLE_JS_API -I /root/firefox-clang/media/libjpeg -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/media/libjpeg -I /root/firefox-clang/media/libjpeg -I /root/firefox-clang/media/libjpeg/src -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/include -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/include/nspr -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/include/nss -D MOZILLA_CLIENT -internal-isystem /usr/lib/llvm-23/lib/clang/23/include -internal-isystem /usr/local/include -internal-isystem /usr/lib/gcc/x86_64-linux-gnu/16/../../../../x86_64-linux-gnu/include -internal-externc-isystem /usr/include/x86_64-linux-gnu -internal-externc-isystem /include -internal-externc-isystem /usr/include -Wno-error=tautological-type-limit-compare -Wno-range-loop-analysis -Wno-error=deprecated-declarations -Wno-error=array-bounds -Wno-error=free-nonheap-object -Wno-error=atomic-alignment -Wno-error=deprecated-builtins -Wno-psabi -Wno-error=builtin-macro-redefined -Wno-unknown-warning-option -Wno-character-conversion -ferror-limit 19 -fstrict-flex-arrays=1 -stack-protector 2 -fstack-clash-protection -ftrivial-auto-var-init=pattern -fgnuc-version=4.2.1 -fskip-odr-check-in-gmf -fdiagnostics-absolute-paths -vectorize-loops -vectorize-slp -analyzer-checker optin.performance.Padding -analyzer-output=html -analyzer-config stable-report-filename=true -mllvm -dwarf-linkage-names=Abstract -faddrsig -fdwarf2-cfi-asm -o /tmp/scan-build-2026-09-01-224014-2642839-1 -x c /root/firefox-clang/media/libjpeg/src/jdicc.c
1/*
2 * jdicc.c
3 *
4 * Copyright (C) 1997-1998, Thomas G. Lane, Todd Newman.
5 * Copyright (C) 2017, D. R. Commander.
6 * For conditions of distribution and use, see the accompanying README.ijg
7 * file.
8 *
9 * This file provides code to read International Color Consortium (ICC) device
10 * profiles embedded in JFIF JPEG image files. The ICC has defined a standard
11 * for including such data in JPEG "APP2" markers. The code given here does
12 * not know anything about the internal structure of the ICC profile data; it
13 * just knows how to get the profile data from a JPEG file while reading it.
14 */
15
16#define JPEG_INTERNALS
17#include "jinclude.h"
18#include "jpeglib.h"
19#include "jerror.h"
20
21
22#define ICC_MARKER(0xE0 + 2) (JPEG_APP00xE0 + 2) /* JPEG marker code for ICC */
23#define ICC_OVERHEAD_LEN14 14 /* size of non-profile data in APP2 */
24
25
26/*
27 * Handy subroutine to test whether a saved marker is an ICC profile marker.
28 */
29
30LOCAL(boolean)static boolean
31marker_is_icc(jpeg_saved_marker_ptr marker)
32{
33 return
34 marker->marker == ICC_MARKER(0xE0 + 2) &&
35 marker->data_length >= ICC_OVERHEAD_LEN14 &&
36 /* verify the identifying string */
37 marker->data[0] == 0x49 &&
38 marker->data[1] == 0x43 &&
39 marker->data[2] == 0x43 &&
40 marker->data[3] == 0x5F &&
41 marker->data[4] == 0x50 &&
42 marker->data[5] == 0x52 &&
43 marker->data[6] == 0x4F &&
44 marker->data[7] == 0x46 &&
45 marker->data[8] == 0x49 &&
46 marker->data[9] == 0x4C &&
47 marker->data[10] == 0x45 &&
48 marker->data[11] == 0x0;
49}
50
51
52/*
53 * See if there was an ICC profile in the JPEG file being read; if so,
54 * reassemble and return the profile data.
55 *
56 * TRUE is returned if an ICC profile was found, FALSE if not. If TRUE is
57 * returned, *icc_data_ptr is set to point to the returned data, and
58 * *icc_data_len is set to its length.
59 *
60 * IMPORTANT: the data at *icc_data_ptr is allocated with malloc() and must be
61 * freed by the caller with free() when the caller no longer needs it.
62 * (Alternatively, we could write this routine to use the IJG library's memory
63 * allocator, so that the data would be freed implicitly when
64 * jpeg_finish_decompress() is called. But it seems likely that many
65 * applications will prefer to have the data stick around after decompression
66 * finishes.)
67 */
68
69GLOBAL(boolean)boolean
70jpeg_read_icc_profile(j_decompress_ptr cinfo, JOCTET **icc_data_ptr,
71 unsigned int *icc_data_len)
72{
73 jpeg_saved_marker_ptr marker;
74 int num_markers = 0;
75 int seq_no;
76 JOCTET *icc_data;
77 unsigned int total_length;
78#define MAX_SEQ_NO255 255 /* sufficient since marker numbers are bytes */
79 char marker_present[MAX_SEQ_NO255 + 1]; /* 1 if marker found */
80 unsigned int data_length[MAX_SEQ_NO255 + 1]; /* size of profile data in marker */
81 unsigned int data_offset[MAX_SEQ_NO255 + 1]; /* offset for data in marker */
82
83 if (icc_data_ptr == NULL((void*)0) || icc_data_len == NULL((void*)0))
1
Assuming 'icc_data_ptr' is not equal to NULL
2
Assuming 'icc_data_len' is equal to NULL
3
Taking true branch
84 ERREXIT(cinfo, JERR_BUFFER_SIZE)((cinfo)->err->msg_code = (JERR_BUFFER_SIZE), (*(cinfo)
->err->error_exit) ((j_common_ptr)(cinfo)))
;
85 if (cinfo->global_state < DSTATE_READY202)
4
Assuming field 'global_state' is >= DSTATE_READY
5
Taking false branch
86 ERREXIT1(cinfo, JERR_BAD_STATE, cinfo->global_state)((cinfo)->err->msg_code = (JERR_BAD_STATE), (cinfo)->
err->msg_parm.i[0] = (cinfo->global_state), (*(cinfo)->
err->error_exit) ((j_common_ptr)(cinfo)))
;
87
88 *icc_data_ptr = NULL((void*)0); /* avoid confusion if FALSE return */
89 *icc_data_len = 0;
6
Dereference of null pointer (loaded from variable 'icc_data_len')
90
91 /* This first pass over the saved markers discovers whether there are
92 * any ICC markers and verifies the consistency of the marker numbering.
93 */
94
95 for (seq_no = 1; seq_no <= MAX_SEQ_NO255; seq_no++)
96 marker_present[seq_no] = 0;
97
98 for (marker = cinfo->marker_list; marker != NULL((void*)0); marker = marker->next) {
99 if (marker_is_icc(marker)) {
100 if (num_markers == 0)
101 num_markers = marker->data[13];
102 else if (num_markers != marker->data[13]) {
103 WARNMS(cinfo, JWRN_BOGUS_ICC)((cinfo)->err->msg_code = (JWRN_BOGUS_ICC), (*(cinfo)->
err->emit_message) ((j_common_ptr)(cinfo), -1))
; /* inconsistent num_markers fields */
104 return FALSE0;
105 }
106 seq_no = marker->data[12];
107 if (seq_no <= 0 || seq_no > num_markers) {
108 WARNMS(cinfo, JWRN_BOGUS_ICC)((cinfo)->err->msg_code = (JWRN_BOGUS_ICC), (*(cinfo)->
err->emit_message) ((j_common_ptr)(cinfo), -1))
; /* bogus sequence number */
109 return FALSE0;
110 }
111 if (marker_present[seq_no]) {
112 WARNMS(cinfo, JWRN_BOGUS_ICC)((cinfo)->err->msg_code = (JWRN_BOGUS_ICC), (*(cinfo)->
err->emit_message) ((j_common_ptr)(cinfo), -1))
; /* duplicate sequence numbers */
113 return FALSE0;
114 }
115 marker_present[seq_no] = 1;
116 data_length[seq_no] = marker->data_length - ICC_OVERHEAD_LEN14;
117 }
118 }
119
120 if (num_markers == 0)
121 return FALSE0;
122
123 /* Check for missing markers, count total space needed,
124 * compute offset of each marker's part of the data.
125 */
126
127 total_length = 0;
128 for (seq_no = 1; seq_no <= num_markers; seq_no++) {
129 if (marker_present[seq_no] == 0) {
130 WARNMS(cinfo, JWRN_BOGUS_ICC)((cinfo)->err->msg_code = (JWRN_BOGUS_ICC), (*(cinfo)->
err->emit_message) ((j_common_ptr)(cinfo), -1))
; /* missing sequence number */
131 return FALSE0;
132 }
133 data_offset[seq_no] = total_length;
134 total_length += data_length[seq_no];
135 }
136
137 if (total_length == 0) {
138 WARNMS(cinfo, JWRN_BOGUS_ICC)((cinfo)->err->msg_code = (JWRN_BOGUS_ICC), (*(cinfo)->
err->emit_message) ((j_common_ptr)(cinfo), -1))
; /* found only empty markers? */
139 return FALSE0;
140 }
141
142 /* Allocate space for assembled data */
143 icc_data = (JOCTET *)malloc(total_length * sizeof(JOCTET));
144 if (icc_data == NULL((void*)0))
145 ERREXIT1(cinfo, JERR_OUT_OF_MEMORY, 11)((cinfo)->err->msg_code = (JERR_OUT_OF_MEMORY), (cinfo)
->err->msg_parm.i[0] = (11), (*(cinfo)->err->error_exit
) ((j_common_ptr)(cinfo)))
; /* oops, out of memory */
146
147 /* and fill it in */
148 for (marker = cinfo->marker_list; marker != NULL((void*)0); marker = marker->next) {
149 if (marker_is_icc(marker)) {
150 JOCTET FAR *src_ptr;
151 JOCTET *dst_ptr;
152 unsigned int length;
153 seq_no = marker->data[12];
154 dst_ptr = icc_data + data_offset[seq_no];
155 src_ptr = marker->data + ICC_OVERHEAD_LEN14;
156 length = data_length[seq_no];
157 while (length--) {
158 *dst_ptr++ = *src_ptr++;
159 }
160 }
161 }
162
163 *icc_data_ptr = icc_data;
164 *icc_data_len = total_length;
165
166 return TRUE1;
167}