[FFmpeg-cvslog] avcodec/aac/aacdec: Clear SFO on error

Michael Niedermayer git at videolan.org
Wed Feb 26 04:20:44 EET 2025


ffmpeg | branch: release/7.1 | Michael Niedermayer <michael at niedermayer.cc> | Fri Feb  7 23:31:20 2025 +0100| [0e5b6a715627b8166ae5276a75ba5459d87b344e] | committer: Michael Niedermayer

avcodec/aac/aacdec: Clear SFO on error

types and SFO become confused for a USAC stream

Fixes: out of array access
Fixes: 383854203/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_AAC_LATM_fuzzer-4996677847547904.fuzz

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
(cherry picked from commit d1be369af6a6f01976be8c80be1177dc524983e5)
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=0e5b6a715627b8166ae5276a75ba5459d87b344e
---

 libavcodec/aac/aacdec.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/libavcodec/aac/aacdec.c b/libavcodec/aac/aacdec.c
index e62bf0f952..39edf73fb7 100644
--- a/libavcodec/aac/aacdec.c
+++ b/libavcodec/aac/aacdec.c
@@ -1745,6 +1745,7 @@ int ff_aac_decode_ics(AACDecContext *ac, SingleChannelElement *sce,
 
     return 0;
 fail:
+    memset(sce->sfo, 0, sizeof(sce->sfo));
     tns->present = 0;
     return ret;
 }



More information about the ffmpeg-cvslog mailing list