aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2024-10-09 18:59:19 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2024-10-25 22:46:39 +0200
commit14f5d67be38dcdf04932e557b7f25975fc91c851 (patch)
tree7393e586fbc02bee49755534e9e69bc1dda4c401
parent08b1bffa49715a9615acc025dfbea252d8409e1f (diff)
downloadffmpeg-14f5d67be38dcdf04932e557b7f25975fc91c851.tar.gz
swscale/rgb2rgb_template: Fix ff_rgb24toyv12_c() with odd height
Fixes: out of array access Fixes: 368143798/clusterfuzz-testcase-minimized-ffmpeg_SWS_fuzzer-6475823425585152 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--libswscale/rgb2rgb_template.c7
1 files changed, 6 insertions, 1 deletions
diff --git a/libswscale/rgb2rgb_template.c b/libswscale/rgb2rgb_template.c
index 197450169a..84b9da0911 100644
--- a/libswscale/rgb2rgb_template.c
+++ b/libswscale/rgb2rgb_template.c
@@ -640,7 +640,7 @@ static inline void uyvytoyv12_c(const uint8_t *src, uint8_t *ydst,
}
/**
- * Height should be a multiple of 2 and width should be a multiple of 2.
+ * width should be a multiple of 2.
* (If this is a problem for anyone then tell me, and I will fix it.)
*/
void ff_rgb24toyv12_c(const uint8_t *src, uint8_t *ydst, uint8_t *udst,
@@ -659,6 +659,11 @@ void ff_rgb24toyv12_c(const uint8_t *src, uint8_t *ydst, uint8_t *udst,
for (y = 0; y < height; y += 2) {
int i;
+ if (y + 1 == height) {
+ ydst2 = ydst1;
+ src2 = src1;
+ }
+
for (i = 0; i < chromWidth; i++) {
unsigned int b11 = src1[6 * i + 0];
unsigned int g11 = src1[6 * i + 1];