On 8/11/2019 9:17 PM, Michael Niedermayer wrote: > Fixes: signed integer overflow: 1 + 2147483647 cannot be represented in type > 'int' > Fixes: > 16041/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5685680656613376 > > Found-by: continuous fuzzing process > https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg > Signed-off-by: Michael Niedermayer <mich...@niedermayer.cc> > --- > libavcodec/hevcdec.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c > index f1934975d5..eed031913a 100644 > --- a/libavcodec/hevcdec.c > +++ b/libavcodec/hevcdec.c > @@ -182,6 +182,8 @@ static int pred_weight_table(HEVCContext *s, > GetBitContext *gb) > for (i = 0; i < s->sh.nb_refs[L0]; i++) { > if (luma_weight_l0_flag[i]) { > int delta_luma_weight_l0 = get_se_golomb(gb); > + if ((int8_t)delta_luma_weight_l0 != delta_luma_weight_l0) > + return AVERROR_INVALIDDATA; > s->sh.luma_weight_l0[i] = (1 << s->sh.luma_log2_weight_denom) + > delta_luma_weight_l0; > s->sh.luma_offset_l0[i] = get_se_golomb(gb); > } > @@ -224,6 +226,8 @@ static int pred_weight_table(HEVCContext *s, > GetBitContext *gb) > for (i = 0; i < s->sh.nb_refs[L1]; i++) { > if (luma_weight_l1_flag[i]) { > int delta_luma_weight_l1 = get_se_golomb(gb); > + if ((int8_t)delta_luma_weight_l1 != delta_luma_weight_l1) > + return AVERROR_INVALIDDATA; > s->sh.luma_weight_l1[i] = (1 << > s->sh.luma_log2_weight_denom) + delta_luma_weight_l1; > s->sh.luma_offset_l1[i] = get_se_golomb(gb); > } >
LGTM. _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-requ...@ffmpeg.org with subject "unsubscribe".