1 From 1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d Mon Sep 17 00:00:00 2001
2 From: Mark Adler <fork@madler.net>
3 Date: Mon, 8 Aug 2022 10:50:09 -0700
4 Subject: [PATCH] Fix extra field processing bug that dereferences NULL
7 The recent commit to fix a gzip header extra field processing bug
8 introduced the new bug fixed here.
11 1 file changed, 2 insertions(+), 2 deletions(-)
13 diff --git a/inflate.c b/inflate.c
14 index 7a7289749..2a3c4fe98 100644
17 @@ -763,10 +763,10 @@ int flush;
19 if (copy > have) copy = have;
21 - len = state->head->extra_len - state->length;
22 if (state->head != Z_NULL &&
23 state->head->extra != Z_NULL &&
24 - len < state->head->extra_max) {
25 + (len = state->head->extra_len - state->length) <
26 + state->head->extra_max) {
27 zmemcpy(state->head->extra + len, next,
28 len + copy > state->head->extra_max ?
29 state->head->extra_max - len : copy);