aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2024-08-12 15:23:56 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2024-08-14 18:20:57 +0200
commite40b23c52abe3356effa552549b2e989708a6e70 (patch)
tree8568202681a3c520d5bb690f3f4b5e866ab3a210
parent598f541ba49cb682dcd74e86858c9a4985149e1f (diff)
downloadffmpeg-e40b23c52abe3356effa552549b2e989708a6e70.tar.gz
tools/target_dec_fuzzer: Check that FFv1 doesnt leave uninitialized memory in its buffers
Sponsored-by: Sovereign Tech Fund Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--tools/target_dec_fuzzer.c9
1 files changed, 8 insertions, 1 deletions
diff --git a/tools/target_dec_fuzzer.c b/tools/target_dec_fuzzer.c
index 794b5b92cc..5fccf2ab8f 100644
--- a/tools/target_dec_fuzzer.c
+++ b/tools/target_dec_fuzzer.c
@@ -129,7 +129,14 @@ static int fuzz_video_get_buffer(AVCodecContext *ctx, AVFrame *frame)
frame->extended_data = frame->data;
for (i = 0; i < 4 && size[i]; i++) {
- frame->buf[i] = av_buffer_allocz(size[i]);
+ switch(ctx->codec_id) {
+ case AV_CODEC_ID_FFV1:
+ frame->buf[i] = av_buffer_alloc(size[i]);
+ break;
+ default:
+ frame->buf[i] = av_buffer_allocz(size[i]);
+ }
+
if (!frame->buf[i])
goto fail;
frame->data[i] = frame->buf[i]->data;