[FFmpeg-devel,1/4] avcodec/hevcdec: Fix memleak of a53_caption

Submitted by Michael Niedermayer on June 30, 2019, 10:16 p.m.

Details

Message ID 20190630221651.12795-1-michael@niedermayer.cc
State New
Headers show

Commit Message

Michael Niedermayer June 30, 2019, 10:16 p.m.
Fixes: 15295/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5675655187922944

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
---
 libavcodec/hevcdec.c | 2 ++
 1 file changed, 2 insertions(+)

Comments

James Almer July 1, 2019, 1:43 a.m.
On 6/30/2019 7:16 PM, Michael Niedermayer wrote:
> Fixes: 15295/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5675655187922944
> 
> Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
> ---
>  libavcodec/hevcdec.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c
> index 515b346535..b5d918d07d 100644
> --- a/libavcodec/hevcdec.c
> +++ b/libavcodec/hevcdec.c
> @@ -3331,6 +3331,8 @@ static av_cold int hevc_decode_free(AVCodecContext *avctx)
>  
>      ff_h2645_packet_uninit(&s->pkt);
>  
> +    ff_hevc_reset_sei(&s->sei);
> +
>      return 0;
>  }

LGTM.
James Almer July 1, 2019, 2:18 a.m.
On 6/30/2019 10:43 PM, James Almer wrote:
> On 6/30/2019 7:16 PM, Michael Niedermayer wrote:
>> Fixes: 15295/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5675655187922944
>>
>> Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
>> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
>> ---
>>  libavcodec/hevcdec.c | 2 ++
>>  1 file changed, 2 insertions(+)
>>
>> diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c
>> index 515b346535..b5d918d07d 100644
>> --- a/libavcodec/hevcdec.c
>> +++ b/libavcodec/hevcdec.c
>> @@ -3331,6 +3331,8 @@ static av_cold int hevc_decode_free(AVCodecContext *avctx)
>>  
>>      ff_h2645_packet_uninit(&s->pkt);
>>  
>> +    ff_hevc_reset_sei(&s->sei);
>> +
>>      return 0;
>>  }
> 
> LGTM.

You could also add it to hevc_decode_flush() while at it.
Michael Niedermayer July 1, 2019, 2:24 p.m.
On Sun, Jun 30, 2019 at 10:43:33PM -0300, James Almer wrote:
> On 6/30/2019 7:16 PM, Michael Niedermayer wrote:
> > Fixes: 15295/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5675655187922944
> > 
> > Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
> > ---
> >  libavcodec/hevcdec.c | 2 ++
> >  1 file changed, 2 insertions(+)
> > 
> > diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c
> > index 515b346535..b5d918d07d 100644
> > --- a/libavcodec/hevcdec.c
> > +++ b/libavcodec/hevcdec.c
> > @@ -3331,6 +3331,8 @@ static av_cold int hevc_decode_free(AVCodecContext *avctx)
> >  
> >      ff_h2645_packet_uninit(&s->pkt);
> >  
> > +    ff_hevc_reset_sei(&s->sei);
> > +
> >      return 0;
> >  }
> 
> LGTM.

will apply

thx
[...]
Michael Niedermayer July 1, 2019, 2:24 p.m.
On Sun, Jun 30, 2019 at 11:18:55PM -0300, James Almer wrote:
> On 6/30/2019 10:43 PM, James Almer wrote:
> > On 6/30/2019 7:16 PM, Michael Niedermayer wrote:
> >> Fixes: 15295/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5675655187922944
> >>
> >> Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> >> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
> >> ---
> >>  libavcodec/hevcdec.c | 2 ++
> >>  1 file changed, 2 insertions(+)
> >>
> >> diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c
> >> index 515b346535..b5d918d07d 100644
> >> --- a/libavcodec/hevcdec.c
> >> +++ b/libavcodec/hevcdec.c
> >> @@ -3331,6 +3331,8 @@ static av_cold int hevc_decode_free(AVCodecContext *avctx)
> >>  
> >>      ff_h2645_packet_uninit(&s->pkt);
> >>  
> >> +    ff_hevc_reset_sei(&s->sei);
> >> +
> >>      return 0;
> >>  }
> > 
> > LGTM.
> 
> You could also add it to hevc_decode_flush() while at it.

will post a patch once i (lightly) tested it

thx

[...]

Patch hide | download patch | download mbox

diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c
index 515b346535..b5d918d07d 100644
--- a/libavcodec/hevcdec.c
+++ b/libavcodec/hevcdec.c
@@ -3331,6 +3331,8 @@  static av_cold int hevc_decode_free(AVCodecContext *avctx)
 
     ff_h2645_packet_uninit(&s->pkt);
 
+    ff_hevc_reset_sei(&s->sei);
+
     return 0;
 }