avcodec/vvc/vvcdec: Do not submit frames without VVCFrameThread

Such frames will crash when pthread functions are called on the NULL pointer

Fixes: member access within null pointer of type 'VVCFrameThread' (aka 'struct VVCFrameThread')
Fixes: 65160/clusterfuzz-testcase-minimized-ffmpeg_BSF_VVC_METADATA_fuzzer-4665241535119360 (partly)
Fixes: 65636/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_VVC_fuzzer-5394745824182272

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
release/7.1
Michael Niedermayer 12 months ago
parent cb9752d897
commit 84ce5ced31
No known key found for this signature in database
GPG Key ID: B18E8928B3948D64
  1. 3
      libavcodec/vvc/vvcdec.c

@ -940,6 +940,9 @@ static int vvc_decode_frame(AVCodecContext *avctx, AVFrame *output,
if (ret < 0)
return ret;
if (!fc->ft)
return avpkt->size;
ret = submit_frame(s, fc, output, got_output);
if (ret < 0)
return ret;

Loading…
Cancel
Save