]> git.sesse.net Git - ffmpeg/commitdiff
avutil/fixed_dsp: Fix integer overflows in butterflies_fixed_c()
authorMichael Niedermayer <michael@niedermayer.cc>
Thu, 16 Jul 2020 20:58:13 +0000 (22:58 +0200)
committerMichael Niedermayer <michael@niedermayer.cc>
Fri, 18 Sep 2020 22:37:45 +0000 (00:37 +0200)
Fixes: signed integer overflow: 0 - -2147483648 cannot be represented in type 'int'
Fixes: 23646/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_AAC_FIXED_fuzzer-5480991098667008
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
libavutil/fixed_dsp.c

index 8c018581df8339c7b4f451818f284dfc4efd7a31..f1b195f1840b113fbc82ca20b5048bf92f79c13c 100644 (file)
@@ -134,9 +134,10 @@ static int scalarproduct_fixed_c(const int *v1, const int *v2, int len)
     return (int)(p >> 31);
 }
 
-static void butterflies_fixed_c(int *v1, int *v2, int len)
+static void butterflies_fixed_c(int *v1s, int *v2, int len)
 {
     int i;
+    unsigned int *v1 = v1s;
 
     for (i = 0; i < len; i++){
         int t = v1[i] - v2[i];