mirror of
https://git.ffmpeg.org/ffmpeg.git
synced 2024-12-22 15:23:11 +00:00
avcodec/hcadec: do not allow code to continue after failed init
Fixes: 62285/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HCA_fuzzer-6247136417087488 Fixes: out of array write Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
addb85ea39
commit
48eeb198a5
@ -538,8 +538,10 @@ static int decode_frame(AVCodecContext *avctx, AVFrame *frame,
|
||||
return AVERROR_INVALIDDATA;
|
||||
} else if (AV_RB16(avpkt->data + 6) <= avpkt->size) {
|
||||
ret = init_hca(avctx, avpkt->data, AV_RB16(avpkt->data + 6));
|
||||
if (ret < 0)
|
||||
if (ret < 0) {
|
||||
c->crc_table = NULL; // signal that init has not finished
|
||||
return ret;
|
||||
}
|
||||
offset = AV_RB16(avpkt->data + 6);
|
||||
if (offset == avpkt->size)
|
||||
return avpkt->size;
|
||||
|
Loading…
Reference in New Issue
Block a user