Fixing out of bounds access in frame_refs[] array. Change-Id: I08f45573e0b2195c09fb6aecacb4c57431a711ea
diff --git a/vp9/encoder/vp9_onyx_int.h b/vp9/encoder/vp9_onyx_int.h index 0a6aab9..d2f42dd 100644 --- a/vp9/encoder/vp9_onyx_int.h +++ b/vp9/encoder/vp9_onyx_int.h
@@ -756,8 +756,10 @@ static void set_ref_ptrs(VP9_COMMON *cm, MACROBLOCKD *xd, MV_REFERENCE_FRAME ref0, MV_REFERENCE_FRAME ref1) { - xd->block_refs[0] = &cm->frame_refs[ref0 - LAST_FRAME]; - xd->block_refs[1] = &cm->frame_refs[ref1 - LAST_FRAME]; + xd->block_refs[0] = &cm->frame_refs[ref0 >= LAST_FRAME ? ref0 - LAST_FRAME + : 0]; + xd->block_refs[1] = &cm->frame_refs[ref1 >= LAST_FRAME ? ref1 - LAST_FRAME + : 0]; } #ifdef __cplusplus