Commit 63d14168 authored by Michael Niedermayer's avatar Michael Niedermayer

avcodec/loco: Fix signed integer overflow in loco_get_rice()

Fixes: signed integer overflow: 2147483647 + 1 cannot be represented in type 'int'
Fixes: 22975/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_LOCO_fuzzer-5658160970072064

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpegSigned-off-by: 's avatarMichael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit aa88cdfd90f5da0683cd6556c75a5ba5740a1c27)
Signed-off-by: 's avatarMichael Niedermayer <michael@niedermayer.cc>
parent 838e17ff
...@@ -82,7 +82,7 @@ static inline void loco_update_rice_param(RICEContext *r, int val) ...@@ -82,7 +82,7 @@ static inline void loco_update_rice_param(RICEContext *r, int val)
static inline int loco_get_rice(RICEContext *r) static inline int loco_get_rice(RICEContext *r)
{ {
int v; unsigned v;
if (r->run > 0) { /* we have zero run */ if (r->run > 0) { /* we have zero run */
r->run--; r->run--;
loco_update_rice_param(r, 0); loco_update_rice_param(r, 0);
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment