diff options
author | Michael Niedermayer <[email protected]> | 2024-11-30 01:48:22 +0100 |
---|---|---|
committer | Michael Niedermayer <[email protected]> | 2025-01-21 22:55:10 +0100 |
commit | ef71552cf970876085d99834abdb8e429aea9730 (patch) | |
tree | bbf9c0feb99b4506653a6a1f5f41f2a5b63ddb81 | |
parent | aec2933344b2b32fc931bdf0b46eef1bd42225ff (diff) |
avcodec/huffyuvdec: Initialize whole output for decode_gray_bitstream()
Fixes: use of uninitialized memory
Fixes: 375286238/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HYMT_fuzzer-6352546854141952
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <[email protected]>
-rw-r--r-- | libavcodec/huffyuvdec.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/libavcodec/huffyuvdec.c b/libavcodec/huffyuvdec.c index a8ccb724f5..c98904d497 100644 --- a/libavcodec/huffyuvdec.c +++ b/libavcodec/huffyuvdec.c @@ -783,6 +783,8 @@ static void decode_gray_bitstream(HYuvDecContext *s, int count) for (i = 0; i < count && BITS_LEFT(re, &s->gb) > 0; i++) { READ_2PIX(s->temp[0][2 * i], s->temp[0][2 * i + 1], 0); } + for (; i < count; i++) + s->temp[0][2 * i] = s->temp[0][2 * i + 1] = 0; } else { for (i = 0; i < count; i++) { READ_2PIX(s->temp[0][2 * i], s->temp[0][2 * i + 1], 0); |