[FFmpeg-devel,1/2] avcodec/diracdec: Check for arith decoder errors in dirac_unpack_block_motion_data()

Submitted by Michael Niedermayer on May 12, 2019, 9:21 p.m.

Details

Message ID 20190512212149.29486-1-michael@niedermayer.cc
State New
Headers show

Commit Message

Michael Niedermayer May 12, 2019, 9:21 p.m.
Fixes: Timeout (54sec -> 188ms)
Fixes: 14585/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_DIRAC_fuzzer-5649933052411904

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
---
 libavcodec/diracdec.c | 5 +++++
 1 file changed, 5 insertions(+)

Patch hide | download patch | download mbox

diff --git a/libavcodec/diracdec.c b/libavcodec/diracdec.c
index a5bb6d5f34..52a1951690 100644
--- a/libavcodec/diracdec.c
+++ b/libavcodec/diracdec.c
@@ -1551,6 +1551,11 @@  static int dirac_unpack_block_motion_data(DiracContext *s)
                 }
         }
 
+    for (i = 0; i < 4 + 2*s->num_refs; i++) {
+        if (arith[i].error)
+            return arith[i].error;
+    }
+
     return 0;
 }