avcodec/wavpack: Check for end of input in wv_unpack_dsd_high()

Fixes: Timeout
Fixes: 50793/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_WAVPACK_fuzzer-4980185027444736

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
pull/388/head
Michael Niedermayer 2 years ago
parent 6b368bcb85
commit 6ad7403bce
No known key found for this signature in database
GPG Key ID: B18E8928B3948D64
  1. 4
      libavcodec/wavpack.c

@ -495,6 +495,8 @@ static int wv_unpack_dsd_high(WavpackFrameContext *s, uint8_t *dst_left, uint8_t
sp[0].fltr0 = 0;
}
if (DSD_BYTE_READY(high, low) && !bytestream2_get_bytes_left(&s->gbyte))
return AVERROR_INVALIDDATA;
while (DSD_BYTE_READY(high, low) && bytestream2_get_bytes_left(&s->gbyte)) {
value = (value << 8) | bytestream2_get_byte(&s->gbyte);
high = (high << 8) | 0xff;
@ -530,6 +532,8 @@ static int wv_unpack_dsd_high(WavpackFrameContext *s, uint8_t *dst_left, uint8_t
sp[1].fltr0 = 0;
}
if (DSD_BYTE_READY(high, low) && !bytestream2_get_bytes_left(&s->gbyte))
return AVERROR_INVALIDDATA;
while (DSD_BYTE_READY(high, low) && bytestream2_get_bytes_left(&s->gbyte)) {
value = (value << 8) | bytestream2_get_byte(&s->gbyte);
high = (high << 8) | 0xff;

Loading…
Cancel
Save