diff --git a/libavcodec/wavarc.c b/libavcodec/wavarc.c index 898c3c2055..caab08cb24 100644 --- a/libavcodec/wavarc.c +++ b/libavcodec/wavarc.c @@ -258,6 +258,10 @@ static int decode_2slp(AVCodecContext *avctx, return AVERROR_EOF; case 8: s->nb_samples = get_urice(gb, 8); + if (s->nb_samples > 570) { + s->nb_samples = 570; + return AVERROR_INVALIDDATA; + } continue; case 7: s->shift = get_urice(gb, 2);