mirror of https://git.ffmpeg.org/ffmpeg.git
avcodec/ttadsp: Fix integer overflows in tta_filter_process_c()
Fixes: signed integer overflow: 822841647 + 1647055738 cannot be represented in type 'int'
Fixes: 39935/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_TTA_fuzzer-4592657142251520
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit f24028c798
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
ffcba1be9a
commit
77fc0df720
|
@ -47,9 +47,9 @@ static void tta_filter_process_c(int32_t *qmi, int32_t *dx, int32_t *dl,
|
|||
*error = *in;
|
||||
*in += (round >> shift);
|
||||
|
||||
dl[4] = -dl[5]; dl[5] = -dl[6];
|
||||
dl[6] = *in - dl[7]; dl[7] = *in;
|
||||
dl[5] += dl[6]; dl[4] += dl[5];
|
||||
dl[4] = -(unsigned)dl[5]; dl[5] = -(unsigned)dl[6];
|
||||
dl[6] = *in -(unsigned)dl[7]; dl[7] = *in;
|
||||
dl[5] += (unsigned)dl[6]; dl[4] += (unsigned)dl[5];
|
||||
}
|
||||
|
||||
av_cold void ff_ttadsp_init(TTADSPContext *c)
|
||||
|
|
Loading…
Reference in New Issue