From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.ffmpeg.org (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTPS id 278364CCA2 for ; Fri, 8 Aug 2025 21:00:20 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.ffmpeg.org (Postfix) with ESMTP id 5C16B68CD50; Sat, 9 Aug 2025 00:00:17 +0300 (EEST) Received: from 0f9ae49ae7c8 (code.ffmpeg.org [188.245.149.3]) by ffbox0-bg.ffmpeg.org (Postfix) with ESMTPS id 34CF768C9CC for ; Sat, 9 Aug 2025 00:00:15 +0300 (EEST) MIME-Version: 1.0 From: michaelni To: ffmpeg-devel@ffmpeg.org Subject: [FFmpeg-devel] =?utf-8?q?=5BPATCH=5D_avcodec/apv=5Fdecode=3A_mak?= =?utf-8?q?e_apv=5Fformat=5Ftable_consistent_with_the_code_and_check_it_?= =?utf-8?b?KFBSICMyMDE4Nyk=?= X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Message-Id: <20250808210017.5C16B68CD50@ffbox0-bg.ffmpeg.org> Date: Sat, 9 Aug 2025 00:00:17 +0300 (EEST) Archived-At: List-Archive: List-Post: PR #20187 opened by michaelni URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20187 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20187.patch Fixes: writing in a null pointer Fixes: 435278398/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_APV_fuzzer-4566392923029504 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer >From 899ca2d31f70a7dac779be96e322cbb5cd521707 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Fri, 8 Aug 2025 22:37:47 +0200 Subject: [PATCH] avcodec/apv_decode: make apv_format_table consistent with the code and check it Fixes: writing in a null pointer Fixes: 435278398/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_APV_fuzzer-4566392923029504 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/apv_decode.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/libavcodec/apv_decode.c b/libavcodec/apv_decode.c index eb47298e2e..c930bc66a1 100644 --- a/libavcodec/apv_decode.c +++ b/libavcodec/apv_decode.c @@ -52,9 +52,9 @@ typedef struct APVDecodeContext { static const enum AVPixelFormat apv_format_table[5][5] = { { AV_PIX_FMT_GRAY8, AV_PIX_FMT_GRAY10, AV_PIX_FMT_GRAY12, AV_PIX_FMT_GRAY14, AV_PIX_FMT_GRAY16 }, { 0 }, // 4:2:0 is not valid. - { AV_PIX_FMT_YUV422P, AV_PIX_FMT_YUV422P10, AV_PIX_FMT_YUV422P12, AV_PIX_FMT_GRAY14, AV_PIX_FMT_YUV422P16 }, - { AV_PIX_FMT_YUV444P, AV_PIX_FMT_YUV444P10, AV_PIX_FMT_YUV444P12, AV_PIX_FMT_GRAY14, AV_PIX_FMT_YUV444P16 }, - { AV_PIX_FMT_YUVA444P, AV_PIX_FMT_YUVA444P10, AV_PIX_FMT_YUVA444P12, AV_PIX_FMT_GRAY14, AV_PIX_FMT_YUVA444P16 }, + { AV_PIX_FMT_YUV422P, AV_PIX_FMT_YUV422P10, AV_PIX_FMT_YUV422P12, AV_PIX_FMT_YUV422P14, AV_PIX_FMT_YUV422P16 }, + { AV_PIX_FMT_YUV444P, AV_PIX_FMT_YUV444P10, AV_PIX_FMT_YUV444P12, AV_PIX_FMT_YUV444P14, AV_PIX_FMT_YUV444P16 }, + { AV_PIX_FMT_YUVA444P, AV_PIX_FMT_YUVA444P10, AV_PIX_FMT_YUVA444P12, 0 ,AV_PIX_FMT_YUVA444P16 }, }; static APVVLCLUT decode_lut; @@ -75,6 +75,9 @@ static int apv_decode_check_format(AVCodecContext *avctx, avctx->pix_fmt = apv_format_table[header->frame_info.chroma_format_idc][bit_depth - 4 >> 2]; + if (!avctx->pix_fmt) + return AVERROR_PATCHWELCOME; + err = ff_set_dimensions(avctx, FFALIGN(header->frame_info.frame_width, 16), FFALIGN(header->frame_info.frame_height, 16)); -- 2.49.1 _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".