From patchwork Mon Aug 23 18:24:56 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Maryam Ebrahimzadeh X-Patchwork-Id: 29743 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a05:6602:2a4a:0:0:0:0 with SMTP id k10csp2318918iov; Mon, 23 Aug 2021 11:25:26 -0700 (PDT) X-Google-Smtp-Source: ABdhPJy4D+foyFPvnLGSEt+U9rw5N2Cuyi+V7sAXqmvEpgm5aIAcbLo886cbFghy5WZCwNaYOV4T X-Received: by 2002:aa7:cb0f:: with SMTP id s15mr38645322edt.190.1629743125924; Mon, 23 Aug 2021 11:25:25 -0700 (PDT) Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id y8si10708706eda.445.2021.08.23.11.25.24; Mon, 23 Aug 2021 11:25:25 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@outlook.com header.s=selector1 header.b=kkWUB4sE; arc=fail (body hash mismatch); spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=outlook.com Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 948BB689F4D; Mon, 23 Aug 2021 21:25:20 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-oln040092072070.outbound.protection.outlook.com [40.92.72.70]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id ECAFF6898DF for ; Mon, 23 Aug 2021 21:25:13 +0300 (EEST) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LTVF1ZJ8lKi6C0blo1SX4qcRRt1poLdoNqGxFiruTBV3vf1Ht8tMKHsNhjujj6KgHiIjneBV+6BnOuUo7ZAnu/NAhmkIkIEvVADLpcwC+Fqe4KEoDMFcTzCj3j37CHLR5382ui6dSAvZ62a1LkKLQJF50x7/LbLHc9FFqyJVNGfhBspIqp0KT7dfDDUc/QHZGiZqu6KjwqiVdFFLTUDsaCGyyWtcWN4qmmzbeNoXuhXKo7/Pp62lbC+d5+U2/sp5wrut5K3l5QT32/FXQFrzXK6a5L0wmWj7SXv1EQYrYyEKk6ytoWSO+h+6AifVxFzIybrOjFAI11SUexDPovLysQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1olM9cc/jCtknn9Zr46u246ppgLpHb0XzKXHPATZ+G0=; b=XBszpMAJ9Qu0s15Q07YtUZ0YvZyZfUJVc/J94Lv90O3oH3L+i0tEM9NrzsdOGgyhX/HCaEXuuNMAIYCxJh++PgY0ig1XKCps5AUSJxoDuoF+k4pJOdrKr1zPkByRxQG+ENMWlkZ4KhpCfM6XhoGWRQfIcoH0uG88153N9W/ZNHWfTalzpkJ1hwrOXKim68xieaV/FuFd2Md6Yc4Ot4tNgf8Oxr3LX5kR7l15NKEpE9qPgEVanaGMkxA2KMQTJsbbSxRb/y4mKSwhRxKScHfUElbhBN81c093TkebTcDG2aB7ly82tbwlDJFy3ZjVfzYgao0+F+lbnUpWac8NLvwFiA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outlook.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1olM9cc/jCtknn9Zr46u246ppgLpHb0XzKXHPATZ+G0=; b=kkWUB4sE0l8viREIpgoPvu8BC/djwCuckprOqotOMRjWu+xQi04jYjYSwS3htuwEaZNsH2BPmpAHnWiJTJdtJ13II6eGM59yZM1H511Hz+Nn/ZUbrquvbriTu7kjfbn3WPisRm9F3zmpC8PbasZF/mhk9O/UG0EthouzVxT6ukANRRajHkW8bBea5sqJEig1cKFk3KpqUnHKEouZVufzbYGZ7rvjL/jp5gM6OfWwQaeRWr59yZSy5VL9UiwhdzmMEjKHvCT3Ow2q9RR1gvcpeREXKGPQvGpdsRgzUFnz5FCGPsJFk9D5Y4mTbG7gCl00IiFrXQhoP0JtBrGF1/gRCQ== Received: from VE1EUR03FT059.eop-EUR03.prod.protection.outlook.com (2a01:111:e400:7e09::4f) by VE1EUR03HT039.eop-EUR03.prod.protection.outlook.com (2a01:111:e400:7e09::397) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4436.19; Mon, 23 Aug 2021 18:25:11 +0000 Received: from PAXP193MB1262.EURP193.PROD.OUTLOOK.COM (2a01:111:e400:7e09::43) by VE1EUR03FT059.mail.protection.outlook.com (2a01:111:e400:7e09::316) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4436.19 via Frontend Transport; Mon, 23 Aug 2021 18:25:11 +0000 X-IncomingTopHeaderMarker: OriginalChecksum:EB5F293CE1D215E9D9D5062014659393ED099DC749C574DF945F445C4DB9C7D8; UpperCasedChecksum:86F6199DAABC79FFD66DEF2029E6204E6A02DB425D76F8C115433E5CD25AFA9F; SizeAsReceived:7176; Count:43 Received: from PAXP193MB1262.EURP193.PROD.OUTLOOK.COM ([fe80::b1f9:e0a6:6946:9c81]) by PAXP193MB1262.EURP193.PROD.OUTLOOK.COM ([fe80::b1f9:e0a6:6946:9c81%2]) with mapi id 15.20.4436.024; Mon, 23 Aug 2021 18:25:11 +0000 From: maryam ebrahimzadeh To: ffmpeg-devel@ffmpeg.org Date: Mon, 23 Aug 2021 14:24:56 -0400 Message-ID: X-Mailer: git-send-email 2.17.1 X-TMN: [BZ2MEAtf9BOw1+PyPhjKlq7uzsxps61x] X-ClientProxiedBy: AM8P189CA0025.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:218::30) To PAXP193MB1262.EURP193.PROD.OUTLOOK.COM (2603:10a6:102:dc::5) X-Microsoft-Original-Message-ID: <20210823182456.2578-1-me22bee@outlook.com> MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 Received: from localhost.localdomain (2.191.135.98) by AM8P189CA0025.EURP189.PROD.OUTLOOK.COM (2603:10a6:20b:218::30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4436.18 via Frontend Transport; Mon, 23 Aug 2021 18:25:10 +0000 X-MS-PublicTrafficType: Email X-IncomingHeaderCount: 43 X-EOPAttributedMessage: 0 X-MS-Office365-Filtering-Correlation-Id: b0a7a4c1-f476-431e-312b-08d966635803 X-MS-TrafficTypeDiagnostic: VE1EUR03HT039: X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: 4UetHlhBpsm2w8yDjCatu9TadDCROX5iv5zvzUyVcY+wzj7QsO9ydIHbSiD7TMAmchiax12whFVj7oA/zRZCtXkakqOcnVPLIuU61IqXF0ThHa97iv5dRluUR+vbdp1WdX+CyGQYoZLzZ7ZQiniBlwaaGFnxseRCEpMIyEL01CFiZ8opre4s7wJfsPUlIPOyFz748HKSp1sGbNs6+0YT0x8NZ1lHIw9OmUD8Dz2rg3QAXSRIt5lOdmorM1qNvueq1L2JO5cBxyUdQoJyOqLjnXR2jDb3x61qyqCPk0rvPpXZxjQAHCG9KG4Qbc1jRbyj2sp+kQ2yw/tkS6vvBRuHDIchtepF/0EHkWKGAd3zm6ghnne/nFVZl2AAtbEvGcsFgRwhuG0zTamhHPMti/vs+eFawlTkm1TozjaEmtTSMdfwQfSfTdjd9HCVGp+blkBd X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: eKdqsiadj4MMzDpE5iGat+zeNYMo1siVzGoPqhrB7xq+KeCeLrBSYFVIqRX4S2tTPhzYVGWLzbkcMwBe/mIf66O8foyhl4Ws2IgITtJzOhicPjOAYUwY1y1BWQVOoc9n0w9zAJcuPPn1rECkItvXCw== X-OriginatorOrg: outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: b0a7a4c1-f476-431e-312b-08d966635803 X-MS-Exchange-CrossTenant-OriginalArrivalTime: 23 Aug 2021 18:25:11.8207 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT059.eop-EUR03.prod.protection.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: Internet X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-Transport-CrossTenantHeadersStamped: VE1EUR03HT039 Subject: [FFmpeg-devel] [PATCH v5 1/1] avcodec/vc1dec: Return value check for init_get_bits X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: ZAK1Fv/Cm7Is avcodec/vc1dec: Return value check for init_get_bits As the second argument for init_get_bits(avctx and buf) can be crafted, a return value check for this function call is necessary so replace init_get_bits with init_get_bits8 and add return value check. --- libavcodec/vc1dec.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/libavcodec/vc1dec.c b/libavcodec/vc1dec.c index 335cd92953..e636fa6160 100644 --- a/libavcodec/vc1dec.c +++ b/libavcodec/vc1dec.c @@ -444,7 +444,9 @@ static av_cold int vc1_decode_init(AVCodecContext *avctx) // the last byte of the extradata is a version number, 1 for the // samples we can decode - init_get_bits(&gb, avctx->extradata, avctx->extradata_size*8); + ret = init_get_bits8(&gb, avctx->extradata, avctx->extradata_size); + if (ret < 0) + return ret; if ((ret = ff_vc1_decode_sequence_header(avctx, v, &gb)) < 0) return ret; @@ -770,8 +772,11 @@ static int vc1_decode_frame(AVCodecContext *avctx, void *data, buf_size2 = vc1_unescape_buffer(buf, buf_size, buf2); } init_get_bits(&s->gb, buf2, buf_size2*8); - } else - init_get_bits(&s->gb, buf, buf_size*8); + } else{ + ret = init_get_bits8(&s->gb, buf, buf_size); + if (ret < 0) + return ret; + } if (v->res_sprite) { v->new_sprite = !get_bits1(&s->gb);