avcodec/snowdec: Avoid integer overflow with huge qlog
Fixes: integer overflow Fixes: 22285/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SNOW_fuzzer-5682428762128384 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
		
							parent
							
								
									d7a2311a2c
								
							
						
					
					
						commit
						38fbf33c72
					
				| @ -117,7 +117,7 @@ static av_always_inline void predict_slice_buffered(SnowContext *s, slice_buffer | |||||||
| static inline void decode_subband_slice_buffered(SnowContext *s, SubBand *b, slice_buffer * sb, int start_y, int h, int save_state[1]){ | static inline void decode_subband_slice_buffered(SnowContext *s, SubBand *b, slice_buffer * sb, int start_y, int h, int save_state[1]){ | ||||||
|     const int w= b->width; |     const int w= b->width; | ||||||
|     int y; |     int y; | ||||||
|     const int qlog= av_clip(s->qlog + b->qlog, 0, QROOT*16); |     const int qlog= av_clip(s->qlog + (int64_t)b->qlog, 0, QROOT*16); | ||||||
|     int qmul= ff_qexp[qlog&(QROOT-1)]<<(qlog>>QSHIFT); |     int qmul= ff_qexp[qlog&(QROOT-1)]<<(qlog>>QSHIFT); | ||||||
|     int qadd= (s->qbias*qmul)>>QBIAS_SHIFT; |     int qadd= (s->qbias*qmul)>>QBIAS_SHIFT; | ||||||
|     int new_index = 0; |     int new_index = 0; | ||||||
| @ -224,7 +224,7 @@ static int decode_q_branch(SnowContext *s, int level, int x, int y){ | |||||||
| 
 | 
 | ||||||
| static void dequantize_slice_buffered(SnowContext *s, slice_buffer * sb, SubBand *b, IDWTELEM *src, int stride, int start_y, int end_y){ | static void dequantize_slice_buffered(SnowContext *s, slice_buffer * sb, SubBand *b, IDWTELEM *src, int stride, int start_y, int end_y){ | ||||||
|     const int w= b->width; |     const int w= b->width; | ||||||
|     const int qlog= av_clip(s->qlog + b->qlog, 0, QROOT*16); |     const int qlog= av_clip(s->qlog + (int64_t)b->qlog, 0, QROOT*16); | ||||||
|     const int qmul= ff_qexp[qlog&(QROOT-1)]<<(qlog>>QSHIFT); |     const int qmul= ff_qexp[qlog&(QROOT-1)]<<(qlog>>QSHIFT); | ||||||
|     const int qadd= (s->qbias*qmul)>>QBIAS_SHIFT; |     const int qadd= (s->qbias*qmul)>>QBIAS_SHIFT; | ||||||
|     int x,y; |     int x,y; | ||||||
|  | |||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user