[FFmpeg-devel] [PATCH 1/2] avcodec/flac_parser: Assert that we do not overrun the link_penalty array

Michael Niedermayer michael at niedermayer.cc
Mon May 13 23:35:17 EEST 2024


Hi

On Mon, May 13, 2024 at 09:07:50AM +0300, Rémi Denis-Courmont wrote:
> 
> 
> Le 5 mai 2024 02:51:59 GMT+03:00, Michael Niedermayer <michael at niedermayer.cc> a écrit :
> >Fixes: CID1454676 Out-of-bounds read
> 
> It's a stretch to call this "fixing". It just asserts that the situation doesn't happen,

yes


> in other words, that it is a false positive from the static analyser.

thanks for reviewing


> 
> The code change looks OK, but the commit description seems misleading.

will apply with "Helps: CID1454676 Out-of-bounds read" instead if "Fixing: ..."

thx

[...]
-- 
Michael     GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB

Dictatorship naturally arises out of democracy, and the most aggravated
form of tyranny and slavery out of the most extreme liberty. -- Plato
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <https://ffmpeg.org/pipermail/ffmpeg-devel/attachments/20240513/f3a5dbd9/attachment.sig>


More information about the ffmpeg-devel mailing list