[FFmpeg-devel,3/8] avcodec/utils: Use more bits for intermediate for AV_CODEC_ID_ADPCM_MS
Checks
Context |
Check |
Description |
andriy/x86_make |
success
|
Make finished
|
andriy/x86_make_fate |
success
|
Make fate finished
|
andriy/PPC64_make |
success
|
Make finished
|
andriy/PPC64_make_fate |
success
|
Make fate finished
|
Commit Message
Fixes: signed integer overflow: 1172577312 * 2 cannot be represented in type 'int'
Fixes: 29924/clusterfuzz-testcase-minimized-ffmpeg_dem_BOA_fuzzer-4882912874594304
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
---
libavcodec/utils.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
Comments
On Mon, Feb 01, 2021 at 11:31:11PM +0100, Michael Niedermayer wrote:
> Fixes: signed integer overflow: 1172577312 * 2 cannot be represented in type 'int'
> Fixes: 29924/clusterfuzz-testcase-minimized-ffmpeg_dem_BOA_fuzzer-4882912874594304
>
> Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
> ---
> libavcodec/utils.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
will apply
[...]
@@ -1786,7 +1786,7 @@ static int get_audio_frame_duration(enum AVCodecID id, int sr, int ch, int ba,
case AV_CODEC_ID_ADPCM_IMA_RAD:
return blocks * ((ba - 4 * ch) * 2 / ch);
case AV_CODEC_ID_ADPCM_MS:
- return blocks * (2 + (ba - 7 * ch) * 2 / ch);
+ return blocks * (2 + (ba - 7 * ch) * 2LL / ch);
case AV_CODEC_ID_ADPCM_MTAF:
return blocks * (ba - 16) * 2 / ch;
}