mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2024-12-23 12:43:46 +02:00
avcodec/hcadec: Check total_band_count against imdct_in size
Fixes: index 128 out of bounds for type 'float [128]' Fixes: 23465/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HCA_fuzzer-5089866596745216 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
c8de8dfba6
commit
2d96c94531
@ -157,6 +157,10 @@ static av_cold int decode_init(AVCodecContext *avctx)
|
||||
} else
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
if (c->total_band_count > FF_ARRAY_ELEMS(c->ch->imdct_in))
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
|
||||
while (get_bits_left(gb) >= 32) {
|
||||
chunk = get_bits_long(gb, 32);
|
||||
if (chunk == MKBETAG('v', 'b', 'r', 0)) {
|
||||
|
Loading…
Reference in New Issue
Block a user