[FFmpeg-devel] [PATCH 4/4] avfilter/af_aiir: Avoid unchecked allocation

Andreas Rheinhardt andreas.rheinhardt at outlook.com
Fri May 24 11:05:20 EEST 2024


W has not been checked at all; allocate it jointly with M
to fix this.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt at outlook.com>
---
 libavfilter/af_aiir.c | 7 +++----
 1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/libavfilter/af_aiir.c b/libavfilter/af_aiir.c
index 324fc367a3..7bd9e37e43 100644
--- a/libavfilter/af_aiir.c
+++ b/libavfilter/af_aiir.c
@@ -828,17 +828,17 @@ static int convert_serial2parallel(AVFilterContext *ctx, int channels)
         double *impulse = av_calloc(length, sizeof(*impulse));
         double *y = av_calloc(length, sizeof(*y));
         double *resp = av_calloc(length, sizeof(*resp));
-        double *M = av_calloc((length - 1) * 2 * nb_biquads, sizeof(*M));
-        double *W = av_calloc((length - 1) * 2 * nb_biquads, sizeof(*W));
+        double *M = av_calloc((length - 1) * nb_biquads, 2 * 2 * sizeof(*M));
+        double *W;
 
         if (!impulse || !y || !resp || !M) {
             av_free(impulse);
             av_free(y);
             av_free(resp);
             av_free(M);
-            av_free(W);
             return AVERROR(ENOMEM);
         }
+        W = M + (length - 1) * 2 * nb_biquads;
 
         impulse[0] = 1.;
 
@@ -877,7 +877,6 @@ static int convert_serial2parallel(AVFilterContext *ctx, int channels)
         av_free(y);
         av_free(resp);
         av_free(M);
-        av_free(W);
     }
 
     return 0;
-- 
2.40.1



More information about the ffmpeg-devel mailing list