[FFmpeg-devel] [PATCH 1/2] avcodec/utils: Ensure 8x8 alignment for ARGO in avcodec_align_dimensions2()

Michael Niedermayer michael at niedermayer.cc
Mon Oct 11 00:39:53 EEST 2021


Fixes: out of array access
Fixes: 39736/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ARGO_fuzzer-4820016722214912

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
---
 libavcodec/utils.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/libavcodec/utils.c b/libavcodec/utils.c
index b4076d94f20..a91a54b0dc4 100644
--- a/libavcodec/utils.c
+++ b/libavcodec/utils.c
@@ -270,6 +270,7 @@ void avcodec_align_dimensions2(AVCodecContext *s, int *width, int *height,
             h_align = 4;
         }
         if (s->codec_id == AV_CODEC_ID_JV ||
+            s->codec_id == AV_CODEC_ID_ARGO ||
             s->codec_id == AV_CODEC_ID_INTERPLAY_VIDEO) {
             w_align = 8;
             h_align = 8;
@@ -300,8 +301,8 @@ void avcodec_align_dimensions2(AVCodecContext *s, int *width, int *height,
         break;
     case AV_PIX_FMT_BGR0:
         if (s->codec_id == AV_CODEC_ID_ARGO) {
-            w_align = 4;
-            h_align = 4;
+            w_align = 8;
+            h_align = 8;
         }
         break;
     default:
-- 
2.17.1



More information about the ffmpeg-devel mailing list