From 5db09574dfd40d3e15db9336a34398405a1c601b Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Sun, 25 Feb 2024 22:06:48 +0100 Subject: [PATCH] avcodec/8bps: Consider width in the minimal size check Fixes: Timeout Fixes: 64479/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_EIGHTBPS_fuzzer-5434435386081280 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/8bps.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavcodec/8bps.c b/libavcodec/8bps.c index 11b9f526b7..0060c46d09 100644 --- a/libavcodec/8bps.c +++ b/libavcodec/8bps.c @@ -63,7 +63,7 @@ static int decode_frame(AVCodecContext *avctx, AVFrame *frame, unsigned int planes = c->planes; int ret; - if (buf_size < planes * height * 2) + if (buf_size < planes * height * (2 + 2*((avctx->width+128)/129))) return AVERROR_INVALIDDATA; if ((ret = ff_get_buffer(avctx, frame, 0)) < 0)