ffmpeg | branch: master | Michael Niedermayer <mich...@niedermayer.cc> | Sun 
May 11 23:18:19 2025 +0200| [05f8c8c4c2b8f3a0b206ecb7e1b5bba68a9820b8] | 
committer: Michael Niedermayer

avformat/matroskadec: check that channels fit in signed 32bit int

Fixes: signed integer overflow: -1384566925600903168 * 16 cannot be represented 
in type 'long'
Fixes: 
407069502/clusterfuzz-testcase-minimized-ffmpeg_dem_WEBM_DASH_MANIFEST_fuzzer-5159255372267520

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <mich...@niedermayer.cc>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=05f8c8c4c2b8f3a0b206ecb7e1b5bba68a9820b8
---

 libavformat/matroskadec.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/libavformat/matroskadec.c b/libavformat/matroskadec.c
index d4b7ae112c..29e35e6dd4 100644
--- a/libavformat/matroskadec.c
+++ b/libavformat/matroskadec.c
@@ -2842,6 +2842,8 @@ static int mka_parse_audio(MatroskaTrack *track, AVStream 
*st,
     par->sample_rate = track->audio.out_samplerate;
     // channel layout may be already set by codec private checks above
     if (!av_channel_layout_check(&par->ch_layout)) {
+        if (track->audio.channels > INT32_MAX)
+            return AVERROR_PATCHWELCOME;
         par->ch_layout.order = AV_CHANNEL_ORDER_UNSPEC;
         par->ch_layout.nb_channels = track->audio.channels;
     }

_______________________________________________
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".

Reply via email to