From ae20be8b5d0b3044b2094127d6ba1f529add50cc Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Fri, 19 Jul 2024 22:20:46 +0200 Subject: [PATCH] avcodec/aac/aacdec_usac: Dont leave invalid max_sfb in the context Fixes: out of array read Fixes: 70363/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_AAC_LATM_fuzzer-6723855293415424.fuzz Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/aac/aacdec_usac.c | 1 + 1 file changed, 1 insertion(+) diff --git a/libavcodec/aac/aacdec_usac.c b/libavcodec/aac/aacdec_usac.c index 32b3c534bf..1b79d19a30 100644 --- a/libavcodec/aac/aacdec_usac.c +++ b/libavcodec/aac/aacdec_usac.c @@ -834,6 +834,7 @@ static int setup_sce(AACDecContext *ac, SingleChannelElement *sce, "Number of scalefactor bands in group (%d) " "exceeds limit (%d).\n", ics->max_sfb, ics->num_swb); + ics->max_sfb = 0; return AVERROR(EINVAL); }