aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2019-10-22 00:09:11 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2019-11-11 20:18:48 +0100
commit00b83748fb1a8fbd5d727a96177be36387e3aa09 (patch)
treed8bed63d43bb87b09edb10a64f57bd4c96068978
parent7339d9aab527fbf501a0bc2676efa8f49c5d1a0c (diff)
downloadffmpeg-00b83748fb1a8fbd5d727a96177be36387e3aa09.tar.gz
avcodec/sbcdec: Fix integer overflows in sbc_synthesize_four()
Fixes: signed integer overflow: 1494495519 + 1494495519 cannot be represented in type 'int' Fixes: 18347/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SBC_fuzzer-5711714661695488 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> (cherry picked from commit 00e469fb6123df92ec3c54ab3b37f77e21d297be) Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--libavcodec/sbcdec.c28
1 files changed, 14 insertions, 14 deletions
diff --git a/libavcodec/sbcdec.c b/libavcodec/sbcdec.c
index 23226d5155..d8ea6855fe 100644
--- a/libavcodec/sbcdec.c
+++ b/libavcodec/sbcdec.c
@@ -227,10 +227,10 @@ static inline void sbc_synthesize_four(struct sbc_decoder_state *state,
/* Distribute the new matrix value to the shifted position */
v[offset[i]] =
- ( ff_synmatrix4[i][0] * frame->sb_sample[blk][ch][0] +
- ff_synmatrix4[i][1] * frame->sb_sample[blk][ch][1] +
- ff_synmatrix4[i][2] * frame->sb_sample[blk][ch][2] +
- ff_synmatrix4[i][3] * frame->sb_sample[blk][ch][3] ) >> 15;
+ (int)( (unsigned)ff_synmatrix4[i][0] * frame->sb_sample[blk][ch][0] +
+ (unsigned)ff_synmatrix4[i][1] * frame->sb_sample[blk][ch][1] +
+ (unsigned)ff_synmatrix4[i][2] * frame->sb_sample[blk][ch][2] +
+ (unsigned)ff_synmatrix4[i][3] * frame->sb_sample[blk][ch][3] ) >> 15;
}
/* Compute the samples */
@@ -239,16 +239,16 @@ static inline void sbc_synthesize_four(struct sbc_decoder_state *state,
/* Store in output, Q0 */
AV_WN16A(&output_frame->data[ch][blk * 8 + i * 2], av_clip_int16(
- ( v[offset[i] + 0] * ff_sbc_proto_4_40m0[idx + 0] +
- v[offset[k] + 1] * ff_sbc_proto_4_40m1[idx + 0] +
- v[offset[i] + 2] * ff_sbc_proto_4_40m0[idx + 1] +
- v[offset[k] + 3] * ff_sbc_proto_4_40m1[idx + 1] +
- v[offset[i] + 4] * ff_sbc_proto_4_40m0[idx + 2] +
- v[offset[k] + 5] * ff_sbc_proto_4_40m1[idx + 2] +
- v[offset[i] + 6] * ff_sbc_proto_4_40m0[idx + 3] +
- v[offset[k] + 7] * ff_sbc_proto_4_40m1[idx + 3] +
- v[offset[i] + 8] * ff_sbc_proto_4_40m0[idx + 4] +
- v[offset[k] + 9] * ff_sbc_proto_4_40m1[idx + 4] ) >> 15));
+ (int)( (unsigned)v[offset[i] + 0] * ff_sbc_proto_4_40m0[idx + 0] +
+ (unsigned)v[offset[k] + 1] * ff_sbc_proto_4_40m1[idx + 0] +
+ (unsigned)v[offset[i] + 2] * ff_sbc_proto_4_40m0[idx + 1] +
+ (unsigned)v[offset[k] + 3] * ff_sbc_proto_4_40m1[idx + 1] +
+ (unsigned)v[offset[i] + 4] * ff_sbc_proto_4_40m0[idx + 2] +
+ (unsigned)v[offset[k] + 5] * ff_sbc_proto_4_40m1[idx + 2] +
+ (unsigned)v[offset[i] + 6] * ff_sbc_proto_4_40m0[idx + 3] +
+ (unsigned)v[offset[k] + 7] * ff_sbc_proto_4_40m1[idx + 3] +
+ (unsigned)v[offset[i] + 8] * ff_sbc_proto_4_40m0[idx + 4] +
+ (unsigned)v[offset[k] + 9] * ff_sbc_proto_4_40m1[idx + 4] ) >> 15));
}
}