[FFmpeg-cvslog] avcodec/pngdec: Clean up on av_frame_ref() failure

Michael Niedermayer git at videolan.org
Thu Feb 1 01:50:17 EET 2018


ffmpeg | branch: release/2.8 | Michael Niedermayer <michael at niedermayer.cc> | Sun Sep 17 02:42:11 2017 +0200| [fd0b42344a7a96f9401c4e1682bd9ded413d0607] | committer: Michael Niedermayer

avcodec/pngdec: Clean up on av_frame_ref() failure

Fixes: memleak
Fixes: 3203/clusterfuzz-testcase-minimized-4514553595428864

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Reviewed-by: James Almer <jamrial at gmail.com>
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
(cherry picked from commit 5480e82d77770e81e897a8c217f3c7f0c13a6de1)
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=fd0b42344a7a96f9401c4e1682bd9ded413d0607
---

 libavcodec/pngdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavcodec/pngdec.c b/libavcodec/pngdec.c
index ba1b39ed8f..ac49954ad0 100644
--- a/libavcodec/pngdec.c
+++ b/libavcodec/pngdec.c
@@ -1303,7 +1303,7 @@ static int decode_frame_png(AVCodecContext *avctx,
         goto the_end;
 
     if ((ret = av_frame_ref(data, s->picture.f)) < 0)
-        return ret;
+        goto the_end;
 
     *got_frame = 1;
 



More information about the ffmpeg-cvslog mailing list