[FFmpeg-cvslog] avcodec/jpegxl_parser: Check get_vlc2()
Michael Niedermayer
git at videolan.org
Fri Dec 29 23:43:44 EET 2023
ffmpeg | branch: master | Michael Niedermayer <michael at niedermayer.cc> | Wed Nov 8 01:48:27 2023 +0100| [850ab8f6da58f8ac1012bef1eb69f7924a8cf620] | committer: Michael Niedermayer
avcodec/jpegxl_parser: Check get_vlc2()
Fixes: shift exponent -1 is negative
Fixes: 63889/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-6009343056936960
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=850ab8f6da58f8ac1012bef1eb69f7924a8cf620
---
libavcodec/jpegxl_parser.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/libavcodec/jpegxl_parser.c b/libavcodec/jpegxl_parser.c
index ceb6191c95..8c45e1a1b7 100644
--- a/libavcodec/jpegxl_parser.c
+++ b/libavcodec/jpegxl_parser.c
@@ -708,6 +708,10 @@ static int read_vlc_prefix(GetBitContext *gb, JXLEntropyDecoder *dec, JXLSymbolD
level1_codecounts[0] = hskip;
for (int i = hskip; i < 18; i++) {
len = level1_lens[prefix_codelen_map[i]] = get_vlc2(gb, level0_table, 4, 1);
+ if (len < 0) {
+ ret = AVERROR_INVALIDDATA;
+ goto end;
+ }
level1_codecounts[len]++;
if (len) {
total_code += (32 >> len);
@@ -753,6 +757,10 @@ static int read_vlc_prefix(GetBitContext *gb, JXLEntropyDecoder *dec, JXLSymbolD
total_code = 0;
for (int i = 0; i < dist->alphabet_size; i++) {
len = get_vlc2(gb, level1_vlc.table, 5, 1);
+ if (len < 0) {
+ ret = AVERROR_INVALIDDATA;
+ goto end;
+ }
if (get_bits_left(gb) < 0) {
ret = AVERROR_BUFFER_TOO_SMALL;
goto end;
More information about the ffmpeg-cvslog
mailing list