mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2025-05-17 06:58:45 +08:00
avformat/matroskadec: check that channels fit in signed 32bit int
Fixes: signed integer overflow: -1384566925600903168 * 16 cannot be represented in type 'long' Fixes: 407069502/clusterfuzz-testcase-minimized-ffmpeg_dem_WEBM_DASH_MANIFEST_fuzzer-5159255372267520 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
@ -2842,6 +2842,8 @@ static int mka_parse_audio(MatroskaTrack *track, AVStream *st,
|
||||
par->sample_rate = track->audio.out_samplerate;
|
||||
// channel layout may be already set by codec private checks above
|
||||
if (!av_channel_layout_check(&par->ch_layout)) {
|
||||
if (track->audio.channels > INT32_MAX)
|
||||
return AVERROR_PATCHWELCOME;
|
||||
par->ch_layout.order = AV_CHANNEL_ORDER_UNSPEC;
|
||||
par->ch_layout.nb_channels = track->audio.channels;
|
||||
}
|
||||
|
Reference in New Issue
Block a user