diff options
author | Michael Niedermayer <michael@niedermayer.cc> | 2024-08-12 15:23:56 +0200 |
---|---|---|
committer | Michael Niedermayer <michael@niedermayer.cc> | 2024-08-14 18:20:57 +0200 |
commit | e40b23c52abe3356effa552549b2e989708a6e70 (patch) | |
tree | 8568202681a3c520d5bb690f3f4b5e866ab3a210 | |
parent | 598f541ba49cb682dcd74e86858c9a4985149e1f (diff) | |
download | ffmpeg-e40b23c52abe3356effa552549b2e989708a6e70.tar.gz |
tools/target_dec_fuzzer: Check that FFv1 doesnt leave uninitialized memory in its buffers
Sponsored-by: Sovereign Tech Fund
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r-- | tools/target_dec_fuzzer.c | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/tools/target_dec_fuzzer.c b/tools/target_dec_fuzzer.c index 794b5b92cc..5fccf2ab8f 100644 --- a/tools/target_dec_fuzzer.c +++ b/tools/target_dec_fuzzer.c @@ -129,7 +129,14 @@ static int fuzz_video_get_buffer(AVCodecContext *ctx, AVFrame *frame) frame->extended_data = frame->data; for (i = 0; i < 4 && size[i]; i++) { - frame->buf[i] = av_buffer_allocz(size[i]); + switch(ctx->codec_id) { + case AV_CODEC_ID_FFV1: + frame->buf[i] = av_buffer_alloc(size[i]); + break; + default: + frame->buf[i] = av_buffer_allocz(size[i]); + } + if (!frame->buf[i]) goto fail; frame->data[i] = frame->buf[i]->data; |