From e8c94e31da65856920434813368956640c771684 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Sun, 8 Dec 2024 02:56:28 +0100 Subject: [PATCH] avformat/mov: free stream_info when the surrounding array is freed Fixes: memleak Fixes: 378408474/clusterfuzz-testcase-minimized-ffmpeg_dem_MOV_fuzzer-5699368121860096 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavformat/mov.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/libavformat/mov.c b/libavformat/mov.c index 26f1bf7e1b..d6aeae048f 100644 --- a/libavformat/mov.c +++ b/libavformat/mov.c @@ -10921,6 +10921,9 @@ static int mov_read_packet(AVFormatContext *s, AVPacket *pkt) // Discard current fragment index if (mov->frag_index.allocated_size > 0) { + for(int i = 0; i < mov->frag_index.nb_items; i++) { + av_freep(&mov->frag_index.item[i].stream_info); + } av_freep(&mov->frag_index.item); mov->frag_index.nb_items = 0; mov->frag_index.allocated_size = 0;