[FFmpeg-devel] [PATCH] avcodec/apv_decode: make apv_format_table consistent with the code and check it (PR #20187)

michaelni code at ffmpeg.org
Sat Aug 9 00:00:15 EEST 2025


PR #20187 opened by michaelni
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20187
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20187.patch

Fixes: writing in a null pointer
Fixes: 435278398/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_APV_fuzzer-4566392923029504

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>


From 899ca2d31f70a7dac779be96e322cbb5cd521707 Mon Sep 17 00:00:00 2001
From: Michael Niedermayer <michael at niedermayer.cc>
Date: Fri, 8 Aug 2025 22:37:47 +0200
Subject: [PATCH] avcodec/apv_decode: make apv_format_table consistent with the
 code and check it

Fixes: writing in a null pointer
Fixes: 435278398/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_APV_fuzzer-4566392923029504

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
---
 libavcodec/apv_decode.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/libavcodec/apv_decode.c b/libavcodec/apv_decode.c
index eb47298e2e..c930bc66a1 100644
--- a/libavcodec/apv_decode.c
+++ b/libavcodec/apv_decode.c
@@ -52,9 +52,9 @@ typedef struct APVDecodeContext {
 static const enum AVPixelFormat apv_format_table[5][5] = {
     { AV_PIX_FMT_GRAY8,    AV_PIX_FMT_GRAY10,     AV_PIX_FMT_GRAY12,     AV_PIX_FMT_GRAY14, AV_PIX_FMT_GRAY16 },
     { 0 }, // 4:2:0 is not valid.
-    { AV_PIX_FMT_YUV422P,  AV_PIX_FMT_YUV422P10,  AV_PIX_FMT_YUV422P12,  AV_PIX_FMT_GRAY14, AV_PIX_FMT_YUV422P16 },
-    { AV_PIX_FMT_YUV444P,  AV_PIX_FMT_YUV444P10,  AV_PIX_FMT_YUV444P12,  AV_PIX_FMT_GRAY14, AV_PIX_FMT_YUV444P16 },
-    { AV_PIX_FMT_YUVA444P, AV_PIX_FMT_YUVA444P10, AV_PIX_FMT_YUVA444P12, AV_PIX_FMT_GRAY14, AV_PIX_FMT_YUVA444P16 },
+    { AV_PIX_FMT_YUV422P,  AV_PIX_FMT_YUV422P10,  AV_PIX_FMT_YUV422P12,  AV_PIX_FMT_YUV422P14, AV_PIX_FMT_YUV422P16 },
+    { AV_PIX_FMT_YUV444P,  AV_PIX_FMT_YUV444P10,  AV_PIX_FMT_YUV444P12,  AV_PIX_FMT_YUV444P14, AV_PIX_FMT_YUV444P16 },
+    { AV_PIX_FMT_YUVA444P, AV_PIX_FMT_YUVA444P10, AV_PIX_FMT_YUVA444P12, 0                   ,AV_PIX_FMT_YUVA444P16 },
 };
 
 static APVVLCLUT decode_lut;
@@ -75,6 +75,9 @@ static int apv_decode_check_format(AVCodecContext *avctx,
     avctx->pix_fmt =
         apv_format_table[header->frame_info.chroma_format_idc][bit_depth - 4 >> 2];
 
+    if (!avctx->pix_fmt)
+        return AVERROR_PATCHWELCOME;
+
     err = ff_set_dimensions(avctx,
                             FFALIGN(header->frame_info.frame_width,  16),
                             FFALIGN(header->frame_info.frame_height, 16));
-- 
2.49.1



More information about the ffmpeg-devel mailing list