diff mbox series

[FFmpeg-devel,1/3] tools/target_dem_fuzzer: Check fmt before dereferencing

Message ID 20220223235057.24625-1-michael@niedermayer.cc
State Accepted
Commit c900f2e42c6ef4b51b5b9237fa6829a4db544d29
Headers show
Series [FFmpeg-devel,1/3] tools/target_dem_fuzzer: Check fmt before dereferencing | expand

Commit Message

Michael Niedermayer Feb. 23, 2022, 11:50 p.m. UTC
Fixes: NULL pointer dereference
Fixes: 44884/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-4656748688965632

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
---
 tools/target_dem_fuzzer.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Michael Niedermayer Feb. 25, 2022, 9:08 p.m. UTC | #1
On Thu, Feb 24, 2022 at 12:50:55AM +0100, Michael Niedermayer wrote:
> Fixes: NULL pointer dereference
> Fixes: 44884/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-4656748688965632
> 
> Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
> ---
>  tools/target_dem_fuzzer.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

will apply

[...]
diff mbox series

Patch

diff --git a/tools/target_dem_fuzzer.c b/tools/target_dem_fuzzer.c
index 687989ccc8..32767a0182 100644
--- a/tools/target_dem_fuzzer.c
+++ b/tools/target_dem_fuzzer.c
@@ -173,7 +173,7 @@  int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
     }
 
     // HLS uses a loop with sleep, we thus must breakout or we timeout
-    if (!strcmp(fmt->name, "hls"))
+    if (fmt && !strcmp(fmt->name, "hls"))
         interrupt_counter &= 31;
 
     if (!io_buffer_size || size / io_buffer_size > maxblocks)