Message ID | 20190713202506.14871-4-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | 8e41675e18682ee14a64acf6139d72d22ce669b6 |
Headers | show |
On Sat, Jul 13, 2019 at 10:25:04PM +0200, Michael Niedermayer wrote: > Fixes: OOM > Fixes: 15575/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5654666781655040 > > Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > --- > libavformat/vividas.c | 7 ++++++- > 1 file changed, 6 insertions(+), 1 deletion(-) will apply [...]
diff --git a/libavformat/vividas.c b/libavformat/vividas.c index 2564a163cb..184d24f374 100644 --- a/libavformat/vividas.c +++ b/libavformat/vividas.c @@ -389,7 +389,12 @@ static void track_header(VividasDemuxContext *viv, AVFormatContext *s, uint8_t offset += av_xiphlacing(&p[offset], data_len[j]); for (j = 0; j < num_data; j++) { - avio_read(pb, &p[offset], data_len[j]); + int ret = avio_read(pb, &p[offset], data_len[j]); + if (ret < data_len[j]) { + st->codecpar->extradata_size = 0; + av_freep(&st->codecpar->extradata); + break; + } offset += data_len[j]; }
Fixes: OOM Fixes: 15575/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5654666781655040 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libavformat/vividas.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-)