[FFmpeg-devel] [PATCH 1/4] avcodec/svq3: dont crash on free_picture(NULL)

Michael Niedermayer michael at niedermayer.cc
Thu Sep 24 23:20:36 EEST 2020


Fixes: NULL dereference
Fixes: 25762/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SVQ3_fuzzer-5716279070294016

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
---
 libavcodec/svq3.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/libavcodec/svq3.c b/libavcodec/svq3.c
index fb7b992496..2da757bee9 100644
--- a/libavcodec/svq3.c
+++ b/libavcodec/svq3.c
@@ -1323,6 +1323,10 @@ static av_cold int svq3_decode_init(AVCodecContext *avctx)
 static void free_picture(AVCodecContext *avctx, SVQ3Frame *pic)
 {
     int i;
+
+    if (!pic)
+        return;
+
     for (i = 0; i < 2; i++) {
         av_freep(&pic->motion_val_buf[i]);
     }
-- 
2.17.1



More information about the ffmpeg-devel mailing list