From c0f315b835174493db2def644df8962149eedcd8 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Tue, 24 Sep 2019 23:50:23 +0200 Subject: [PATCH] avcodec/sbcdec: Initialize number of channels Fixes: out of array access Fixes: 17609/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SBC_fuzzer-5758729319874560 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Reviewed-by: Paul B Mahol Reviewed-by: Moritz Barsnick Signed-off-by: Michael Niedermayer (cherry picked from commit 02fb6a214717d40487cae2b06f13b14fabb6e101) Signed-off-by: Michael Niedermayer --- libavcodec/sbcdec.c | 1 + 1 file changed, 1 insertion(+) diff --git a/libavcodec/sbcdec.c b/libavcodec/sbcdec.c index 546b38c106..937946e2d2 100644 --- a/libavcodec/sbcdec.c +++ b/libavcodec/sbcdec.c @@ -348,6 +348,7 @@ static int sbc_decode_frame(AVCodecContext *avctx, if (frame_length <= 0) return frame_length; + avctx->channels = frame->channels = sbc->frame.channels; frame->format = AV_SAMPLE_FMT_S16P; frame->nb_samples = sbc->frame.blocks * sbc->frame.subbands;