avformat/mov: fix the check for the heif item parsing loop

Fixes: Null pointer dereference
Fixes: 67861/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5352628142800896

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: James Almer <jamrial@gmail.com>
This commit is contained in:
James Almer 2024-04-27 19:38:13 -03:00
parent 59767636c7
commit 31327c2d07
1 changed files with 2 additions and 1 deletions

View File

@ -9440,7 +9440,8 @@ static int mov_parse_tiles(AVFormatContext *s)
break;
}
if (k == grid->nb_tiles) {
if (k == mov->nb_heif_item) {
av_assert0(loop);
av_log(s, AV_LOG_WARNING, "HEIF item id %d referenced by grid id %d doesn't "
"exist\n",
tile_id, grid->item->item_id);