1
0
mirror of https://github.com/FFmpeg/FFmpeg.git synced 2024-12-23 12:43:46 +02:00

swscale/output: used unsigned for bit accumulation

Fixes: Integer overflow
Fixes: 368725672/clusterfuzz-testcase-minimized-ffmpeg_SWS_fuzzer-5009093023563776

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
Michael Niedermayer 2024-10-09 20:39:07 +02:00
parent 14f5d67be3
commit 3fe3014405
No known key found for this signature in database
GPG Key ID: B18E8928B3948D64

View File

@ -664,7 +664,7 @@ yuv2mono_2_c_template(SwsInternal *c, const int16_t *buf[2],
if (c->dither == SWS_DITHER_ED) {
int err = 0;
int acc = 0;
unsigned acc = 0;
for (i = 0; i < dstW; i +=2) {
int Y;
@ -686,7 +686,8 @@ yuv2mono_2_c_template(SwsInternal *c, const int16_t *buf[2],
c->dither_error[0][i] = err;
} else {
for (i = 0; i < dstW; i += 8) {
int Y, acc = 0;
int Y;
unsigned acc = 0;
Y = (buf0[i + 0] * yalpha1 + buf1[i + 0] * yalpha) >> 19;
accumulate_bit(acc, Y + d128[0]);
@ -721,7 +722,7 @@ yuv2mono_1_c_template(SwsInternal *c, const int16_t *buf0,
if (c->dither == SWS_DITHER_ED) {
int err = 0;
int acc = 0;
unsigned acc = 0;
for (i = 0; i < dstW; i +=2) {
int Y;
@ -743,7 +744,7 @@ yuv2mono_1_c_template(SwsInternal *c, const int16_t *buf0,
c->dither_error[0][i] = err;
} else {
for (i = 0; i < dstW; i += 8) {
int acc = 0;
unsigned acc = 0;
accumulate_bit(acc, ((buf0[i + 0] + 64) >> 7) + d128[0]);
accumulate_bit(acc, ((buf0[i + 1] + 64) >> 7) + d128[1]);
accumulate_bit(acc, ((buf0[i + 2] + 64) >> 7) + d128[2]);