From patchwork Mon Sep 23 21:32:43 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51772 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:d154:0:b0:48e:c0f8:d0de with SMTP id bt20csp2734604vqb; Mon, 23 Sep 2024 14:33:02 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCWZYqnqMJ5L00fTtSdmEly6PT23QNb+0pkAeGKjJl8njmaSJcOVg87i3f49vhz61FS3+l4kazVuP/CRg7ORdS4c@gmail.com X-Google-Smtp-Source: AGHT+IFtxBfPKyy02+wpnnxh5mMgXU1+c5dqTU7obp/sTe9J6h/QdD9nNFt3PO1hMtnCCo+3Wy88 X-Received: by 2002:a2e:be08:0:b0:2f1:a30c:cd15 with SMTP id 38308e7fff4ca-2f7cb33787bmr61766981fa.36.1727127182104; Mon, 23 Sep 2024 14:33:02 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727127182; cv=none; d=google.com; s=arc-20240605; b=k4whe+fU0hOhuKcsomryCGRhACinNPROJJKMSRHqQUsixWt06IDoAe2nZ37TS3arYl 1i6L4GXcW8KNZfaWUS20R6hYjDO2fSanYwVwGKAVhEdbKVU1RK5dkuhNPv/09WWVNTXo 7HtdNLi7jauS3uPdQGuduTOVWSB8YiZYmrLdCgWErYwK+JzRn+FFwkKlMrtj1V2ZYXDj idc2ZVN0DORrUMGmxAoaxbzeLYxgP87xXv2//rPird+jbsSuso+pRn2WlDqmYQ8KSKlZ AdJbtOXj/rPQB6d+RlWsgRdFpF/qOAjdCMpci+wXUj25Q4N7Hn5qMekZj2zWiS+s4HL2 GhxQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:message-id:date:to:from :dkim-signature:delivered-to; bh=21LOo3GJ5nwHMv7c85dNqL3d+W6di2DfNMGtMPY+Mkk=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=ayEAYAIEeIb8Rof9zxoUIF9484iT/Tpq/65He81hD8gq0Yz0hyI/C65NRmfrWiBoHd 86rP/GYpnwN6fQrthz7YCuBzbhjlsyomXEpbIT71iVhVMkzdI1dEwXNzRzb3cDzlAsQb MELv/Hj+DuNFgHDdkye+uDqB1BYc18JzY56wRNqN5dsFqqBZpciTDz4iunIs7bp8KJwe RDy9l+AC9OmC/yawC0eRM2LVBdrPbvRihKUFhaGFHYVZr5iMXDPfMIx1hSl9orCc/urt bdfbdyPkIqDtleqa/W4oB1Ay+z947lpwKkFczH+XuAShSYGZk78U2xdrI6luBy/4xWC5 ZIeA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=pJ2sxoyw; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id 38308e7fff4ca-2f8d282f50dsi429771fa.128.2024.09.23.14.33.01; Mon, 23 Sep 2024 14:33:02 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=pJ2sxoyw; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 5648568DA40; Tue, 24 Sep 2024 00:32:57 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay8-d.mail.gandi.net (relay8-d.mail.gandi.net [217.70.183.201]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 1E10868CB1B for ; Tue, 24 Sep 2024 00:32:51 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id 698DB1BF204 for ; Mon, 23 Sep 2024 21:32:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127170; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=N3r6xssL8yvL7pJ1nPlbe+iammy4v8v96Js5X4HdZRs=; b=pJ2sxoywmz+Dcy9rhM81sO/+2qdRMCpfJ6+bH4kDyIxnAkZSWMc29WBtaxHkNIOvOz5kKB eUDZ1Bh1XzSk8VGHssGVBLnmYQl4w4w86ZeXmul67JAMO6loNf9r5+zCZ95qeRg8Aib05g FikVtdsvYuenJDJxinh2NH00yPVKg0WZ/6SyqoXSs7BgCUE7E1TJarSBYFhK51sruAIzOy R0OOlBFRUWdmSu8BWF+MnR6pexzbkJ+3YRJIxyz5QPdqrA8qk1wqJ8dK8Qq7SJKB3KAENs 2ZlEKqsNShfeey2Yj5VMR622o5X5aVxb8VjYM0uCS5+JFRFvfFbtcSk4Tv3tvA== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:43 +0200 Message-ID: <20240923213249.3256534-1-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 1/7] avcodec/ilbcdec: Initialize tempbuff2 X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: +Whn7IY5T2Yu Fixes: Use of uninitialized value Fixes: 71350/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ILBC_fuzzer-6322020827070464 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/ilbcdec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/ilbcdec.c b/libavcodec/ilbcdec.c index ba1da168bc0..7fea39b43ca 100644 --- a/libavcodec/ilbcdec.c +++ b/libavcodec/ilbcdec.c @@ -658,7 +658,7 @@ static void get_codebook(int16_t * cbvec, /* (o) Constructed codebook vector * int16_t k, base_size; int16_t lag; /* Stack based */ - int16_t tempbuff2[SUBL + 5]; + int16_t tempbuff2[SUBL + 5] = {0}; /* Determine size of codebook sections */ base_size = lMem - cbveclen + 1; From patchwork Mon Sep 23 21:32:44 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51776 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:d154:0:b0:48e:c0f8:d0de with SMTP id bt20csp2737049vqb; Mon, 23 Sep 2024 14:39:18 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCViKrO84f8ic7yo4A20MMcMHgkIEZVuBs9x1URWVtPrTa4jYZidoPHOLbbMZou/1UNY28+sH5uCeQSPysvLSP2W@gmail.com X-Google-Smtp-Source: AGHT+IFRd896SDDcpYHrUR/KphLJp5AyRfjY0Tm6sJ2s8Iwgt0jrLKktDT4Ol//t2mYNux4GIxcO X-Received: by 2002:a05:6512:2254:b0:536:9f02:17b4 with SMTP id 2adb3069b0e04-536ac334260mr7648423e87.40.1727127558598; Mon, 23 Sep 2024 14:39:18 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727127558; cv=none; d=google.com; s=arc-20240605; b=MujKS63K4ZRXedrWsTLQScKVsKCmFbVdiSVQqJn51J8BUWn23NkeaNXFH6nJbQ86Tt L5gtI0iOwSE8rXbdoDFOCuzeMW3Jexl4Am2TgwYMsnjEQ1R/IuIjajpFVNBZEPDealqi /Bd3ITcHoKjX1gvgrfs3MiZuFO/iVzJWnrEnH4ElqIf0+leKC3aogN5YXD+DsXdd4e62 0DXRQeyIvmH2/ie4OFk1nM5uibaPfvkSoisd1AYbuD4HExSPcQoN/ep1EBw2clNc5qnR F/Q6cWCwOrIPhurGReaWtHM51QyQzwZcLIWnwlHJS2xrgov7o/lxeGabNHbC+VauWwH0 ydog== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:references:in-reply-to:message-id :date:to:from:dkim-signature:delivered-to; bh=UBOTGvQJer76qxl24n567QT1ZB1eKxK3VkdVKbB5tfI=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=gKYa6MQTsZlSVRy3BKnL3dyXpir4IitwWYyCn/nXw79WZ1WA/4Imoi/pk8uQkJGME9 NSLWNCuC+IHBWT3fCK9NVJ5nTIS16dSYyUIkbwJLwgoYVg+LFebK/a6WOzCjxZi9hOIU QY9PsOWzflTOOXn4ny9bqkTvHZNSLj1OCWjR52eygKonrgkfEGuAkk3DQyHntZBaQIIT z8l2k9ad8QRDtyyiEVuAd8F+caT4/4pAsEfWc5Yjg2B1RNeSzRG7Hy2jG4yvjQrd9NxH HqMVp+rTLQbkLsRe7c0jXdMxGBNWOGjdX3Fw5Hj5Iqc1S0vRthQaWLQ0p9yzchEJx1Q3 jrYw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=alL8BKpz; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id a640c23a62f3a-a9392f2d203si3483566b.90.2024.09.23.14.39.18; Mon, 23 Sep 2024 14:39:18 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=alL8BKpz; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 66ED668DA68; Tue, 24 Sep 2024 00:32:59 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay5-d.mail.gandi.net (relay5-d.mail.gandi.net [217.70.183.197]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 9B6D168DA47 for ; Tue, 24 Sep 2024 00:32:52 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id C582C1C0002 for ; Mon, 23 Sep 2024 21:32:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127171; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cPsVxrXrBF5oKBQc+pCM8iU7Tfqwv5+dooS+dksu0bk=; b=alL8BKpzqaeRyGBoND6r3Opcx3mbO9hEiRJsNjX/NlqgdRK2772qCaRiRvkDI+ev9lls/g ndAStrGmpukhEmO7+wET/F6EQpwJ0TZe8XHw1STXixFiRZY5rmEKko7IWbI+Gb738bwDQ3 BR1DSzP2fD7cwhzjYROkPjzmPJT9KTd9N7z0y5eXxFbwrjR2r3IWCbNxnzs3F11Um8lRTe QH+7Xi7ay6Xh/4CPpfaiRxGQ6bjcIOgMD9VODo0uucJjz3N4R7A9l3CBpPFvqIrIyHxzu9 JMYBOAyFUV6dMClDzQpaN83114T4MEn5No4TET18J8jYbJ4CG6DB6yEUqGQfxw== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:44 +0200 Message-ID: <20240923213249.3256534-2-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 In-Reply-To: <20240923213249.3256534-1-michael@niedermayer.cc> References: <20240923213249.3256534-1-michael@niedermayer.cc> MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 2/7] avformat/mxfdec: Check avio_read() success in mxf_decrypt_triplet() X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: HCQbs20G2/VQ Fixes: Use of uninitialized memory Fixes: 71444/clusterfuzz-testcase-minimized-ffmpeg_dem_MXF_fuzzer-5448597561212928 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavformat/mxfdec.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/libavformat/mxfdec.c b/libavformat/mxfdec.c index 24f4ed1c33d..b232c45f47d 100644 --- a/libavformat/mxfdec.c +++ b/libavformat/mxfdec.c @@ -671,7 +671,8 @@ static int mxf_decrypt_triplet(AVFormatContext *s, AVPacket *pkt, KLVPacket *klv if (size < 32 || size - 32 < orig_size || (int)orig_size != orig_size) return AVERROR_INVALIDDATA; avio_read(pb, ivec, 16); - avio_read(pb, tmpbuf, 16); + if (avio_read(pb, tmpbuf, 16) != 16) + return AVERROR_INVALIDDATA; if (mxf->aesc) av_aes_crypt(mxf->aesc, tmpbuf, tmpbuf, 1, ivec, 1); if (memcmp(tmpbuf, checkv, 16)) From patchwork Mon Sep 23 21:32:45 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51773 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:d154:0:b0:48e:c0f8:d0de with SMTP id bt20csp2734747vqb; Mon, 23 Sep 2024 14:33:21 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCWR8+LqUunMPFsl1Aem77Yp9gTEqF9JM0r9dqTIVnrkxWsiCL3DY5eAFWS9SXz4nc5BNS/fXwy0wb7CHMtUJ/SB@gmail.com X-Google-Smtp-Source: AGHT+IFiR4RSaHBeO3c4TMRMwmjHS4p+hGPjV0dSN2qkRPJdPmaMklHcpu3U0BQqnZWn66xeyTOP X-Received: by 2002:a2e:bc81:0:b0:2f7:5c24:1cad with SMTP id 38308e7fff4ca-2f7cb353d6fmr19941381fa.12.1727127200990; Mon, 23 Sep 2024 14:33:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727127200; cv=none; d=google.com; s=arc-20240605; b=GnZOTAVytC1VWCEXTaMw/6eb/3pJu5a775X2+eYEKZpikDN6Pe/a/gyNVxODR0ooct tlPQoUMUsGDy1H3/VUm0VLK1WmCQDdZPeyhhvx1qCw5j3Q/IAQdp8VLoyun8cySohVl1 OZGbRBYfvDXpJm/wE/thzqkeOuUqXI9pzPcKpD5PJW9UyMywkFrhyca+G3hT0CMvigxp X92nj5C4fin1sbNkgN4rOY/0acHWiTXAjwNohX+cQmwGv6ajPQXSoxWiEm54OReXBedL p+llxlUCLWD1zPd41Agxau7rhA7P84TReBL5KZ29d205kIZy7FoMZUYIlQHe986wy+ph xK1Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:references:in-reply-to:message-id :date:to:from:dkim-signature:delivered-to; bh=war5Zmv9Fm3ztDBFK2ACz6HaVrMggYVfHGfOBvW7WFM=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=gkwxRvc/fQ6mJiNBJHwNwQWqWBnRe1yUuqmXp8rr1IutX7yUS7U7Xqb2aMqVMuBLW9 9aBSnLYZ3hhQSZSOCgBWX58/+qDcODYwqEudUIV5cj0eP/EHPcK5gMZ+gBu3VjT8oTL0 0i4Ps3tJSaTTSlpnHC3TVvtxuATldU5IjxcQ/HxDZ17BpRZIXxpa+885cwYg1Pv+cVNO nu/zW7C6JZuk/ly+ByzIiKm9LmH2DKQp4DV23pC6RnTZGcr3FAHkFRtBXILkZxixy2oF 7gsPVaJY9oLnF6WyMoqHu06pwTzeMwHY9v7ctQsbjhmqUYgRrC0n+yIJjHV418mvk9YM DPTQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=MsodTtmG; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id 38308e7fff4ca-2f8d28c4192si358541fa.614.2024.09.23.14.33.20; Mon, 23 Sep 2024 14:33:20 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=MsodTtmG; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id A31DF68DAC2; Tue, 24 Sep 2024 00:33:00 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay4-d.mail.gandi.net (relay4-d.mail.gandi.net [217.70.183.196]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id A437868CB1B for ; Tue, 24 Sep 2024 00:32:53 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id 0A795E0003 for ; Mon, 23 Sep 2024 21:32:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127173; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wFlPpSCkzS49REK4tO4L1jQhqQ6SPPlkBFDJw+o0Uec=; b=MsodTtmGt5Ubm4BnSNA1eMK7j9aKGBgJiYHwJJgX/afdQMHKUKM2QWcUhE46lXDTg5Q++N rvDyzjXo4gJg5/zl/J5czrBMITTM/5XG5haJeRNVBHD3/HevVn1g8G1n62wPc5q6sqc9fx k2rX5AaKC9J6eeEtEm7AeSPKFM2tl4w50Xshp10F2OM5Qn1evFpUPVlLM1PVNHF1rc6Q9d UwJYRN0LTMrtpyWbs2g39slSEPWVuZoDMSkHvKXPwrqJLixNdtT049/Ws5z9ZD6BksnWaQ oT5NqnhZXhbYgf329H0Cw9ssXof2vVI5KvrWQqvw04HYkJXxBA7xpigxNt2Aog== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:45 +0200 Message-ID: <20240923213249.3256534-3-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 In-Reply-To: <20240923213249.3256534-1-michael@niedermayer.cc> References: <20240923213249.3256534-1-michael@niedermayer.cc> MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 3/7] avcodec/eatgq: move array to where it is used X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: jhH6s5zHSVBA Signed-off-by: Michael Niedermayer --- libavcodec/eatgq.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/eatgq.c b/libavcodec/eatgq.c index d326c053907..190c57f1c00 100644 --- a/libavcodec/eatgq.c +++ b/libavcodec/eatgq.c @@ -156,7 +156,6 @@ static int tgq_decode_mb(TgqContext *s, GetByteContext *gbyte, { int mode; int i; - int8_t dc[6]; mode = bytestream2_get_byte(gbyte); if (mode > 12) { @@ -173,6 +172,7 @@ static int tgq_decode_mb(TgqContext *s, GetByteContext *gbyte, tgq_idct_put_mb(s, s->block, frame, mb_x, mb_y); bytestream2_skip(gbyte, mode); } else { + int8_t dc[6]; if (mode == 3) { memset(dc, bytestream2_get_byte(gbyte), 4); dc[4] = bytestream2_get_byte(gbyte); From patchwork Mon Sep 23 21:32:46 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51774 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:d154:0:b0:48e:c0f8:d0de with SMTP id bt20csp2734820vqb; Mon, 23 Sep 2024 14:33:30 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCU0sMKVTD+75Ey3vyMj23tlPhnufJS8h93Q6mx5Fgi85PoCz+Ir3OpPUJnGMqogjDislfQp4PEasybPM50qOOdn@gmail.com X-Google-Smtp-Source: AGHT+IHYV3VrFKk9uTmVQSMf0mAuALtLIvmfDmPtXFAsa5zBplZSXSZPgHwm8z9ygJkE4rDubJse X-Received: by 2002:a17:907:7ba2:b0:a80:f54a:f428 with SMTP id a640c23a62f3a-a90d4fc3130mr630988666b.2.1727127210264; Mon, 23 Sep 2024 14:33:30 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727127210; cv=none; d=google.com; s=arc-20240605; b=dS6CP5OPx8/XVZn3hp6zQyFcIrP9+xNWF0PT69+1kY03jeNK/bsYANOK/dJ9en36fA 8t+pz8PR6FJJKim6gEdMnq2PRH22QQkAbeek8odpd0UOz0ugVUochVMaVhDInvYjLDyJ bZlBAuPF9sAg7IQLYCgfsrOwvdXsv1bc+OL8DZZcrZf9uu/zxa2F9N3SWBITBdqbLQDo J0wTMbeTijvSmx2CfnCIeGYK3Eak7rLfHzvH0YjFum1r9+IydTD7ibziMUz7KKF90qDn anIJsCfhOKT56zerRo9Ure1G77Iaf7jJ06IA9ayDjmDi3XW/LrKOA95WMRIYuhLqRVu6 hlxw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:references:in-reply-to:message-id :date:to:from:dkim-signature:delivered-to; bh=uHXcxzRJ6EtGmoeofye8Bwv6ov7h/ZIGkkkUd9yXQj0=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=DUN6YtZL6z1tTOA0k7ouTcaA89820OsiZrzZhwjT8GUsDqW5FDI7WAvOqgR7uapv1/ vS7MZRzh84h1zN3TpNYiTwTjZeett8zZh1jSdIwd2GQcev5CqCCcpE/zMXRL5J+l5NlT 9f9tZv+maTCuBd3bUejjzhzPb5sie+6BAV935Xe9kHMmWMk6aJU9bi6ZmD4g05gns/iZ q6qxOj5tpfb9+cTOkWyXXiAI9mT8/Nhdi2/pgD0vcVU186/IbPcxTkOeic7DkbnfsiPJ K8LvP7lEhBi3LpDxaXWqdFPp0En8UvKswRObs40u4cD8ESn9w77gpNfVYQpUVV2OsflK LSlA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=ZAYwGXWs; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id a640c23a62f3a-a9392f2b874si2925466b.17.2024.09.23.14.33.29; Mon, 23 Sep 2024 14:33:30 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=ZAYwGXWs; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 1364A68DAE4; Tue, 24 Sep 2024 00:33:04 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay1-d.mail.gandi.net (relay1-d.mail.gandi.net [217.70.183.193]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id B390768DA58 for ; Tue, 24 Sep 2024 00:32:54 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id 03B46240004 for ; Mon, 23 Sep 2024 21:32:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127174; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=d2yzuvUf2P0ZdjQMo/twjpuXYNankjoFluM/JNswiGE=; b=ZAYwGXWsUM0FqyxtQtdZdjd0+xTyf9QSXVkkCZ4/7KGbKdcR4pD2hlWwW68cP212Z+Rdi0 8rhdjsYy+yvxuhl7xRHiHGUpsi9G+xKJImEp/WU8KzgfUxtwufcgbJhiwlw3RHPpWIdie6 gBeq9nq3hq8n/NYfGNqZEFsOIm3yqLbVEr4+6LGFFeZl+0U1A9QC1/m1WlCXx83QnHDXQG HlpniAtAhXqGqXkxSW/wIQR/BzF4VMgNni9sC6JkO/wTNM2BWUmGdqrBqU0ZN/XKQjicuW sRHb0XxKSaPb74fWuZMS+1RTl88qZHTihxG74bHqaJ1/Tu574Uf2MleEFSmpsg== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:46 +0200 Message-ID: <20240923213249.3256534-4-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 In-Reply-To: <20240923213249.3256534-1-michael@niedermayer.cc> References: <20240923213249.3256534-1-michael@niedermayer.cc> MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 4/7] avcodec/eatgq: Check bytestream2_get_buffer() for failure X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: 1p74EB7ojTk9 Fixes: Use of uninitialized memory Fixes: 71546/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_EATGQ_fuzzer-5607656650244096 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/eatgq.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/libavcodec/eatgq.c b/libavcodec/eatgq.c index 190c57f1c00..57129dce51e 100644 --- a/libavcodec/eatgq.c +++ b/libavcodec/eatgq.c @@ -178,7 +178,8 @@ static int tgq_decode_mb(TgqContext *s, GetByteContext *gbyte, dc[4] = bytestream2_get_byte(gbyte); dc[5] = bytestream2_get_byte(gbyte); } else if (mode == 6) { - bytestream2_get_buffer(gbyte, dc, 6); + if (bytestream2_get_buffer(gbyte, dc, 6) != 6) + return AVERROR_INVALIDDATA; } else if (mode == 12) { for (i = 0; i < 6; i++) { dc[i] = bytestream2_get_byte(gbyte); From patchwork Mon Sep 23 21:32:47 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51775 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:d154:0:b0:48e:c0f8:d0de with SMTP id bt20csp2734900vqb; Mon, 23 Sep 2024 14:33:40 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCUIXwZhe9/CfXtPNdUPaAY3ynQgwhY8k+DGwzZo70yzU1xMAPg05jCfG12bXt+eSDDxW7+fhJ+148N2f5p0vaAW@gmail.com X-Google-Smtp-Source: AGHT+IFk/O2mY1mSXfk5JFSU7EJEkWR9ab96F+TXll0/UcuBxRZuHZrvs9wFkyiqo+Ctu91eSp6y X-Received: by 2002:a2e:be20:0:b0:2f7:5915:436e with SMTP id 38308e7fff4ca-2f7cc3572a2mr66309141fa.2.1727127220689; Mon, 23 Sep 2024 14:33:40 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727127220; cv=none; d=google.com; s=arc-20240605; b=MshlaS+sEXS1su+jnzgMKumpw6KGW/VPnmVRWt1u0G5U3UHKuDiyqyieL0hgXDy4rL Ld0wNgb7ey7BiY5QEFCq19DH6NtyqrYTRu/5bUgHPoboNnUMMyO8Xxyxr7/40OQVVRc5 FGQvtLzOvBAB8LcrQEDipXnpVUSC+P+IlVcM0ZGZnkz8W+9v2TieMpo828RF3xqDgqQt ETPbMieOAWf93OQIAQmlTzTNYInfKJIkLxUxqtlHGuV6NKSCprbvvpB80e5CHanzQ7Fa iAjg7NmEgsRmPPUqhiBMvLecJcCT/O499CqgWpgm5w2fWdIT9/WKgub1rKEd6Y8Pdsqu 1FZQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:references:in-reply-to:message-id :date:to:from:dkim-signature:delivered-to; bh=SJIFQp8fZV8qwRzEn8L6u6gCx4sjlkByYEQvGs2DT/M=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=YolvuTtQr4j7Tvk2GctNKcvGP/ayyoKWcRK9vNEmWbGpILoXMhhljJo2Eg8SFxrAGY Q0110iQEBo2+lWo7DZRgCZwlsjq8XneWoMmafMKpZ0SWMQfSGl7HuNcx/XY6L7oDZTPS EH4TVLVRrYSjsuMtkFP7zS2IWDwFT2L5G6iTO0tfiOL8b9vcytRxVian8UdqIh5dndgg P4gfPmhSO8fA61ME+YdcZFlAfheodkzXWr76rO2KW2VIy6nu18vXFJ4aFYc79VRdRkzb ZmT4uuVZv1DOBExk4f2TY7vsd3vOqaq8W1X7NtgFhHzlyZ0FWOurUEaKxUcFaSvv7FXy /Rcg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b="i/SMyy1z"; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id 38308e7fff4ca-2f8d282f08csi420371fa.9.2024.09.23.14.33.40; Mon, 23 Sep 2024 14:33:40 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b="i/SMyy1z"; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id A800968DB57; Tue, 24 Sep 2024 00:33:05 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay9-d.mail.gandi.net (relay9-d.mail.gandi.net [217.70.183.199]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id C778668DAC6 for ; Tue, 24 Sep 2024 00:32:55 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id 1F117FF802 for ; Mon, 23 Sep 2024 21:32:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127175; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=d5VQIdVEi8DRzZJqTPTwulyx/igsBFeyQ5M7Mq5G4Gk=; b=i/SMyy1zobaZQ+R/SJof0B3KY8F1BrOruosnBJ9JJQZQ5HXIb75zPO2l8NOD4WGBPxh5uJ hPARQ4nroCz3edxQ4uc0h2W7kCD47DXjFJf0C13g4V6oSSBEOYvNdXkhFuiHUXgZvrXglR OOq8BAGJ8LGtamLXFYOtsbzXGx8qahLK8Nznl/hXvRehM26uIeG8gHEm1G/AtHBCGABG7s Y4WfWkNZn6euaBaUVzLJA64WAJnjxPR71Y3sWMr/Miq7HktzIfUVjqsYfYJ0lE8ycYfEAF y32WDfkttz5amO0O7C/1lRBpc8svt8FLhQsh02/3GGLvOxwqdYjH3FlRYN4JTg== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:47 +0200 Message-ID: <20240923213249.3256534-5-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 In-Reply-To: <20240923213249.3256534-1-michael@niedermayer.cc> References: <20240923213249.3256534-1-michael@niedermayer.cc> MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 5/7] avformat/qcp: Check for read failure in header X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: WtuY8O5sZJpj Fixes: Use of uninitialized value Fixes: 71551/clusterfuzz-testcase-minimized-ffmpeg_dem_QCP_fuzzer-4647386712965120 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavformat/qcp.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/libavformat/qcp.c b/libavformat/qcp.c index fdf18618d23..13a479a11e6 100644 --- a/libavformat/qcp.c +++ b/libavformat/qcp.c @@ -105,7 +105,8 @@ static int qcp_read_header(AVFormatContext *s) st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO; st->codecpar->ch_layout = (AVChannelLayout)AV_CHANNEL_LAYOUT_MONO; - avio_read(pb, buf, 16); + if (avio_read(pb, buf, 16) != 16) + return AVERROR_INVALIDDATA; if (is_qcelp_13k_guid(buf)) { st->codecpar->codec_id = AV_CODEC_ID_QCELP; } else if (!memcmp(buf, guid_evrc, 16)) { From patchwork Mon Sep 23 21:32:48 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51777 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:d154:0:b0:48e:c0f8:d0de with SMTP id bt20csp2738773vqb; Mon, 23 Sep 2024 14:44:20 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCVjYfnieB5nFsmy2YCaninVOJ/fBSP+BIqL4znVAzfTGrZDjK34nDVZ/UzxyzfdKPq0iIHN4JbB2oISjofG7f0e@gmail.com X-Google-Smtp-Source: AGHT+IFn8ZwxmwyuFTrz+8wpToewlGIV8/7OeYNJPphTH43yyzbr/LWt1lfs94ij+NXGn6NNHEf/ X-Received: by 2002:a05:6512:2811:b0:530:e323:b1cd with SMTP id 2adb3069b0e04-536ad3d7255mr7010875e87.40.1727127860130; Mon, 23 Sep 2024 14:44:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727127860; cv=none; d=google.com; s=arc-20240605; b=cpCeXwRv+hBQRgkGqhP65S6v8iAMHnc56wC64y8t67+0jQEY3ZEE/XANoeC/KC6+qB t8XUTBg9ZBkKEfxwRxxyUxhr1bgcYqoSf2Te4IHMSwIkEkx3W/Yi0TXUujBCyCdcuuKb FVON112e97vEwKVDEaEH4HfPYPm0uzFWRSwID9tLs/DHp6nRPZhHDFzBSSq55sToc3QS s5mEy2OZzbgEx+kK/S+AotqZ53f79pteI3I6nstjtZgSKJ8E1qyIqBnUlRYRFOC8Wgd+ vbLQhHwGVD8SMYuKJqCefGYRdzWQr6HSsI9IY+cVl5/Lw4M4u6j+6r0Z271N1uRUjW2X uC+w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:references:in-reply-to:message-id :date:to:from:dkim-signature:delivered-to; bh=5S2DAmOhdfP9BS3Sf2NfznhYQc8ZfmPuYnVD3UFPjn8=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=CBzBx0qrrt5Ecj8lGaMASXyhfFNMoO4gmsIujgr6vXeWkb2qbBF9zVfCnvNEctoG+K WE4sILlpQM1fdoUf4sq5ZnJUZ7UIzX4vBKyWSti6eFQPSY3nRUImfInD7visrOHyYaG2 ECJg/oXNkeM5TZO9Z3txRMc8BDcW3Ax/sBJf2IncDAjbGt/yWQXll5vEwY8PNRaMcxxl mx5jdcbH4kFfSWqO8Q89qyDQ/F9S+hHGXQDS9ft9/fx7qtrccsxaPHtMHGhfUKLf+Gch hhIDGwLwNknQnCX4jk8GykEpC5JgzUJFYWXxOkVkyXkMF+Y44qP+BZxsf0flfH6/wXvt u/cg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=aOfqzXn6; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id 2adb3069b0e04-537a85ee55asi31421e87.136.2024.09.23.14.44.19; Mon, 23 Sep 2024 14:44:20 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b=aOfqzXn6; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 017BB68DB29; Tue, 24 Sep 2024 00:33:07 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay3-d.mail.gandi.net (relay3-d.mail.gandi.net [217.70.183.195]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 06A3E68DA4D for ; Tue, 24 Sep 2024 00:32:56 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id 4278C60004 for ; Mon, 23 Sep 2024 21:32:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tBNvjiL80ZYZscNqMk27NWNaAXIiY0Udx8IAdH9/7Jk=; b=aOfqzXn61KSEf7PK+g+6voRcwhKO0n2Dm4BSppu9GIzLhSDxrqTswhhdiRyFTizX1FHV2L b3zX7cODJqCtBHyD9rwoEz5WoSWEIec19rIAGAMGuE+nOxzo3qTFB4Hs0Pg/IPNCN3POol leCOkrEBpHK++/a/INLK98QGphhU614v1J2hgTVjuoU+7X9yxXmk36qp4J6Iy0tQAJpgtV xgNUcShwog3+EsRWJuS29yHvmLmdx/hSo0MeR4IJ1qNsBDqIWoMy0nOqVfswAN4vdeD3ju hhA2vSVYdkOgNf3uD79OgDEMM7jwjhGv2qOTi4gC6R4PJ7YOQWSadUVnc/XLuw== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:48 +0200 Message-ID: <20240923213249.3256534-6-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 In-Reply-To: <20240923213249.3256534-1-michael@niedermayer.cc> References: <20240923213249.3256534-1-michael@niedermayer.cc> MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 6/7] avcodec/get_bits: dont add a null to a 0 X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: WqfA8tcURhKf Fixes: undefined behavior Fixes: 71747/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5427736120721408 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/get_bits.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/get_bits.h b/libavcodec/get_bits.h index fe2f6378b45..beeff87a79b 100644 --- a/libavcodec/get_bits.h +++ b/libavcodec/get_bits.h @@ -528,7 +528,7 @@ static inline int init_get_bits(GetBitContext *s, const uint8_t *buffer, s->buffer = buffer; s->size_in_bits = bit_size; s->size_in_bits_plus8 = bit_size + 8; - s->buffer_end = buffer + buffer_size; + s->buffer_end = buffer ? buffer + buffer_size : NULL; s->index = 0; return ret; From patchwork Mon Sep 23 21:32:49 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Niedermayer X-Patchwork-Id: 51778 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a59:ad12:0:b0:48e:c0f8:d0de with SMTP id w18csp22554vqy; Mon, 23 Sep 2024 16:29:20 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCVLdC2/ZmvfUXo0bDdc+3jePu3y7U5aVpN0aL+CutzR8JeCkhf/KUtA2Zw12W1g4MOTqiv44/S22ZPDA8VUDiSM@gmail.com X-Google-Smtp-Source: AGHT+IHgEesrmw0Kprffm9/JnT4pwnJSIQ5Cv8NCDkh1St2KzRlOJ6XN5JkL+Pu89QhC7QbOBPRC X-Received: by 2002:a05:6512:3d94:b0:52c:76ac:329b with SMTP id 2adb3069b0e04-536ac2f5febmr9175210e87.35.1727134159864; Mon, 23 Sep 2024 16:29:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1727134159; cv=none; d=google.com; s=arc-20240605; b=PlHtuOEbz/XVWN7EidsWDqQsKaDUhhXnhwbfXopWOEBh7SPleC9XtbeOqQ557KCHuo LslgSIxKl4JXUnemLHHrYtC7knNwUFvDLY5CvtBLK4fV23xv2AOuCXfTAJDw+KrOf0f+ uMP3CCjADoZf85uQM5sCq0SWgjTv2M12S3PQdyHeXInDZCZfwfslvnBqrc5CWk9hiiZp 7xQ5s/bwnj4ghwrl457pBqPb+eTHkpTE8dyjqnZ9jwa/FkXxmunhUGk4zHLorUBXp3QY nIDVeFbWYM79HqyVwQA5RfP5l0KBONiCykfMyO+H27b7mkg2DAywranIVAILgRN+yZfa Ealw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=sender:errors-to:content-transfer-encoding:reply-to:list-subscribe :list-help:list-post:list-archive:list-unsubscribe:list-id :precedence:subject:mime-version:references:in-reply-to:message-id :date:to:from:dkim-signature:delivered-to; bh=cQ9mdL5yt5u7030cRSRN3ieeZp0Ar4CxlyBdNe8LUZU=; fh=e5zN9xSzcxLA6bGo3lF+CqTbY/oLwzApV03EO/RBfgQ=; b=j8x5xkD19e+7T+PIhMmG6oquDFunMo7RtUUAlwVD2obafCT94wDKNuWdwckMJGDHZL IPXLzXIU0PaiipTMnN9WK/K8ikG5j+bM4osL2Dh0Cp88y7sB3p66UFgCDjBezG6E8NqT eKqp+FHTsQ2hqik7H2FxDwSoRutMlJty9W3m6A9Qsl3/GxdhUvAkIwNoCsPqi842xIRF k+1lK8dG6nNRLlWrcZClZPUQx3V1QFlfB77G3P4V8pzNG6D3Cs7WmKCOz/encDhMEUkn pRN85/D0mAjnNLRlkriTuWh8xivSmOkClWNJCm+PV3HjJxPedLSwbNZKcTTTs6lSliWK W/tA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b="fgH/j+/K"; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id a640c23a62f3a-a9392f2b1b6si13379566b.101.2024.09.23.16.29.19; Mon, 23 Sep 2024 16:29:19 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@niedermayer.cc header.s=gm1 header.b="fgH/j+/K"; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id F169468DB83; Tue, 24 Sep 2024 00:33:07 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from relay5-d.mail.gandi.net (relay5-d.mail.gandi.net [217.70.183.197]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 9B65A68DAE2 for ; Tue, 24 Sep 2024 00:32:57 +0300 (EEST) Received: by mail.gandi.net (Postfix) with ESMTPSA id F035A1C0004 for ; Mon, 23 Sep 2024 21:32:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=niedermayer.cc; s=gm1; t=1727127177; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=EI0mfQlRmWnxBxRdBOdfJliN1aCTNC8r/hcjbIm+n9k=; b=fgH/j+/Kz1VgxoTL13HMO4yCnhfkXuhg51UyElPZ9LyanyuqJTcHvv6+w0ZxXdHt9/HbxP 7CPN2AGYFFdAfYhD5rFRdalIWKkStGMKPX9sh36pvlP/zFb5LbKR6x4QxuHw9tc/xdk7n9 YFVvKvX12XbSwmsYXjdZ1N82kCIJbNzrBde7QH2xXNpdaiqRwW+0ujrLUZIYKVcZNIEVF6 6WBUiLQ2nBB4OsUzbGdc5a1v3Sfae8tVWG1hoZxDCp8UFcUC311NmYI/bg2rNxZ9l+mfcI kGb3D43aT/vDjz6xfdJXSQV5DOCTMMRfOIMCjItYXOjRn38lyQO8/3fv0d9KPQ== From: Michael Niedermayer To: FFmpeg development discussions and patches Date: Mon, 23 Sep 2024 23:32:49 +0200 Message-ID: <20240923213249.3256534-7-michael@niedermayer.cc> X-Mailer: git-send-email 2.46.1 In-Reply-To: <20240923213249.3256534-1-michael@niedermayer.cc> References: <20240923213249.3256534-1-michael@niedermayer.cc> MIME-Version: 1.0 X-GND-Sasl: michael@niedermayer.cc Subject: [FFmpeg-devel] [PATCH 7/7] avcodec/hevc/hevcdec: initialize qp_y_tab X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: nBPdRYQMUIKF This does not replicate on my setup, thus this is a blind fix based on ossfuzz trace Fixes: use of uninitialized value Fixes: 71747/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5427736120721408 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/hevc/hevcdec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/hevc/hevcdec.c b/libavcodec/hevc/hevcdec.c index d915d74d22e..0b50bbd2754 100644 --- a/libavcodec/hevc/hevcdec.c +++ b/libavcodec/hevc/hevcdec.c @@ -127,7 +127,7 @@ static int pic_arrays_init(HEVCLayerContext *l, const HEVCSPS *sps) l->filter_slice_edges = av_mallocz(ctb_count); l->tab_slice_address = av_malloc_array(pic_size_in_ctb, sizeof(*l->tab_slice_address)); - l->qp_y_tab = av_malloc_array(pic_size_in_ctb, + l->qp_y_tab = av_calloc(pic_size_in_ctb, sizeof(*l->qp_y_tab)); if (!l->qp_y_tab || !l->filter_slice_edges || !l->tab_slice_address) goto fail;