mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2024-12-23 12:43:46 +02:00
avcodec/wavpack: Check shift
Fixes: runtime error: shift exponent 255 is too large for 32-bit type 'unsigned int' Fixes: 894/clusterfuzz-testcase-4841537823309824 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
b15818642b
commit
423375d4f0
@ -861,6 +861,12 @@ static int wavpack_decode_block(AVCodecContext *avctx, int block_no,
|
||||
s->and = 1;
|
||||
s->shift = val[3];
|
||||
}
|
||||
if (s->shift > 31) {
|
||||
av_log(avctx, AV_LOG_ERROR,
|
||||
"Invalid INT32INFO, shift = %d (> 31)\n", s->shift);
|
||||
s->and = s->or = s->shift = 0;
|
||||
continue;
|
||||
}
|
||||
/* original WavPack decoder forces 32-bit lossy sound to be treated
|
||||
* as 24-bit one in order to have proper clipping */
|
||||
if (s->hybrid && bpp == 4 && s->post_shift < 8 && s->shift > 8) {
|
||||
|
Loading…
Reference in New Issue
Block a user