Message ID | 20211226133723.575-1-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | d6b2357eddca392ee137cb2a92ff178a0a7d0cce |
Headers | show |
Series | [FFmpeg-devel] avcodec/speexdec: Consider mode in frame size check | expand |
Context | Check | Description |
---|---|---|
andriy/make_x86 | success | Make finished |
andriy/make_fate_x86 | success | Make fate finished |
andriy/make_ppc | success | Make finished |
andriy/make_fate_ppc | fail | Make fate failed |
On Sun, Dec 26, 2021 at 02:37:23PM +0100, Michael Niedermayer wrote: > No speex samples with non default frame sizes are known (to me) > the official speexenc seems to only generate the 3 default ones. > Thus it may be that the fuzzer samples where the first non default > values encountered by the decoder. > Possibly the "<" should be "!=" > > If someone has a valid speex file with non default frame sizes that > would be interesting! > > Fixes: out of array access > Fixes: 42821/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SPEEX_fuzzer-5640695772217344 > > Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > --- > libavcodec/speexdec.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) will apply [...]
diff --git a/libavcodec/speexdec.c b/libavcodec/speexdec.c index 1c33607db27..dcbdf5e010a 100644 --- a/libavcodec/speexdec.c +++ b/libavcodec/speexdec.c @@ -1419,7 +1419,7 @@ static int parse_speex_extradata(AVCodecContext *avctx, return AVERROR_INVALIDDATA; s->bitrate = bytestream_get_le32(&buf); s->frame_size = bytestream_get_le32(&buf); - if (s->frame_size < NB_FRAME_SIZE) + if (s->frame_size < NB_FRAME_SIZE << s->mode) return AVERROR_INVALIDDATA; s->vbr = bytestream_get_le32(&buf); s->frames_per_packet = bytestream_get_le32(&buf);
No speex samples with non default frame sizes are known (to me) the official speexenc seems to only generate the 3 default ones. Thus it may be that the fuzzer samples where the first non default values encountered by the decoder. Possibly the "<" should be "!=" If someone has a valid speex file with non default frame sizes that would be interesting! Fixes: out of array access Fixes: 42821/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SPEEX_fuzzer-5640695772217344 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libavcodec/speexdec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)