aboutsummaryrefslogtreecommitdiffstats
path: root/libavfilter/f_realtime.c
diff options
context:
space:
mode:
authorAndreas Rheinhardt <andreas.rheinhardt@outlook.com>2020-05-27 10:54:44 +0200
committerAndreas Rheinhardt <andreas.rheinhardt@outlook.com>2022-04-01 13:20:56 +0200
commitf93ca3a2780727e7bde6d1e96ed5eca96b90a57d (patch)
tree6822d51540f33fbf7869159db720a364cc0bbe08 /libavfilter/f_realtime.c
parent4e61bf403f334f93135dc031d8ff3a64d8743e0b (diff)
downloadffmpeg-f93ca3a2780727e7bde6d1e96ed5eca96b90a57d.tar.gz
avcodec/vp9_superframe_bsf: Check for existence of data before reading it
Packets without data need to be handled specially in order to avoid undefined reads. Pass these packets through unchanged in case there are no cached packets* and error out in case there are cached packets: Returning the packet would mess with the order of the packets; if one returned the zero-sized packet before the superframe that will be created from the packets in the cache, the zero-sized packet would overtake the packets in the cache; if one returned the packet later, the packets that complete the superframe will overtake the zero-sized packet. *: This case e.g. encompasses the scenario of updated extradata side-data at the end. Fixes: Out of array read Fixes: 45722/clusterfuzz-testcase-minimized-ffmpeg_BSF_VP9_SUPERFRAME_fuzzer-5173378975137792 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@outlook.com> (cherry picked from commit c12e8c97b13f33897bd9c6095432c9740504f5c7)
Diffstat (limited to 'libavfilter/f_realtime.c')
0 files changed, 0 insertions, 0 deletions