mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2024-12-23 12:43:46 +02:00
avcodec/jpegxl_parser: Check get_vlc2()
Fixes: shift exponent -1 is negative Fixes: 63889/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-6009343056936960 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
0ecc1f0e48
commit
850ab8f6da
@ -708,6 +708,10 @@ static int read_vlc_prefix(GetBitContext *gb, JXLEntropyDecoder *dec, JXLSymbolD
|
||||
level1_codecounts[0] = hskip;
|
||||
for (int i = hskip; i < 18; i++) {
|
||||
len = level1_lens[prefix_codelen_map[i]] = get_vlc2(gb, level0_table, 4, 1);
|
||||
if (len < 0) {
|
||||
ret = AVERROR_INVALIDDATA;
|
||||
goto end;
|
||||
}
|
||||
level1_codecounts[len]++;
|
||||
if (len) {
|
||||
total_code += (32 >> len);
|
||||
@ -753,6 +757,10 @@ static int read_vlc_prefix(GetBitContext *gb, JXLEntropyDecoder *dec, JXLSymbolD
|
||||
total_code = 0;
|
||||
for (int i = 0; i < dist->alphabet_size; i++) {
|
||||
len = get_vlc2(gb, level1_vlc.table, 5, 1);
|
||||
if (len < 0) {
|
||||
ret = AVERROR_INVALIDDATA;
|
||||
goto end;
|
||||
}
|
||||
if (get_bits_left(gb) < 0) {
|
||||
ret = AVERROR_BUFFER_TOO_SMALL;
|
||||
goto end;
|
||||
|
Loading…
Reference in New Issue
Block a user