aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2020-07-16 22:58:13 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2020-09-19 00:37:45 +0200
commit4a02ae49c26395fc3ae2d38c733a2a13bd3080e7 (patch)
treed41e56a39b7ee6dba2c4a344c0a30c64d859a8a4
parent6401a5d4b836a08090bc82e5d3101cc1873ae2a7 (diff)
downloadffmpeg-4a02ae49c26395fc3ae2d38c733a2a13bd3080e7.tar.gz
avutil/fixed_dsp: Fix integer overflows in butterflies_fixed_c()
Fixes: signed integer overflow: 0 - -2147483648 cannot be represented in type 'int' Fixes: 23646/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_AAC_FIXED_fuzzer-5480991098667008 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--libavutil/fixed_dsp.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/libavutil/fixed_dsp.c b/libavutil/fixed_dsp.c
index 8c018581df..f1b195f184 100644
--- a/libavutil/fixed_dsp.c
+++ b/libavutil/fixed_dsp.c
@@ -134,9 +134,10 @@ static int scalarproduct_fixed_c(const int *v1, const int *v2, int len)
return (int)(p >> 31);
}
-static void butterflies_fixed_c(int *v1, int *v2, int len)
+static void butterflies_fixed_c(int *v1s, int *v2, int len)
{
int i;
+ unsigned int *v1 = v1s;
for (i = 0; i < len; i++){
int t = v1[i] - v2[i];