Message ID | 20221029191353.2973-1-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | 2532b20b17ec557f1b925bfc41c00e7d4e17356c |
Headers | show |
Series | [FFmpeg-devel,1/4] avformat/replaygain: avoid undefined / negative abs | expand |
Context | Check | Description |
---|---|---|
yinshiyou/make_loongarch64 | success | Make finished |
yinshiyou/make_fate_loongarch64 | success | Make fate finished |
andriy/make_x86 | success | Make finished |
andriy/make_fate_x86 | success | Make fate finished |
On Sat, Oct 29, 2022 at 09:13:50PM +0200, Michael Niedermayer wrote: > Fixes: signed integer overflow: -2147483648 * 100000 cannot be represented in type 'int' > Fixes: 52060/clusterfuzz-testcase-minimized-ffmpeg_dem_MP3_fuzzer-5131616708329472 > > Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > --- > libavformat/replaygain.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) will apply [...]
diff --git a/libavformat/replaygain.c b/libavformat/replaygain.c index 24f5c74183..915bcb2382 100644 --- a/libavformat/replaygain.c +++ b/libavformat/replaygain.c @@ -60,7 +60,7 @@ static int32_t parse_value(const char *value, int32_t min) } } - if (abs(db) > (INT32_MAX - mb) / 100000) + if (llabs(db) > (INT32_MAX - mb) / 100000) return min; return db * 100000 + sign * mb;
Fixes: signed integer overflow: -2147483648 * 100000 cannot be represented in type 'int' Fixes: 52060/clusterfuzz-testcase-minimized-ffmpeg_dem_MP3_fuzzer-5131616708329472 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libavformat/replaygain.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)