Re: [FFmpeg-devel] [PATCH 3/4] avcodec/sbcdec: Fix integer overflows in sbc_synthesize_four()

2019-11-09 Thread Michael Niedermayer
On Tue, Oct 22, 2019 at 04:27:03PM +0200, Michael Niedermayer wrote:
> Fixes: signed integer overflow: 1494495519 + 1494495519 cannot be represented 
> in type 'int'
> Fixes: 
> 18347/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SBC_fuzzer-5711714661695488
> 
> Found-by: continuous fuzzing process 
> https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> Signed-off-by: Michael Niedermayer 
> ---
>  libavcodec/sbcdec.c | 28 ++--
>  1 file changed, 14 insertions(+), 14 deletions(-)

will apply

[...]
-- 
Michael GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB

it is not once nor twice but times without number that the same ideas make
their appearance in the world. -- Aristotle


signature.asc
Description: PGP signature
___
ffmpeg-devel mailing list
ffmpeg-devel@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-devel

To unsubscribe, visit link above, or email
ffmpeg-devel-requ...@ffmpeg.org with subject "unsubscribe".

[FFmpeg-devel] [PATCH 3/4] avcodec/sbcdec: Fix integer overflows in sbc_synthesize_four()

2019-10-22 Thread Michael Niedermayer
Fixes: signed integer overflow: 1494495519 + 1494495519 cannot be represented 
in type 'int'
Fixes: 
18347/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SBC_fuzzer-5711714661695488

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
---
 libavcodec/sbcdec.c | 28 ++--
 1 file changed, 14 insertions(+), 14 deletions(-)

diff --git a/libavcodec/sbcdec.c b/libavcodec/sbcdec.c
index 23226d5155..d8ea6855fe 100644
--- a/libavcodec/sbcdec.c
+++ b/libavcodec/sbcdec.c
@@ -227,10 +227,10 @@ static inline void sbc_synthesize_four(struct 
sbc_decoder_state *state,
 
 /* Distribute the new matrix value to the shifted position */
 v[offset[i]] =
-( ff_synmatrix4[i][0] * frame->sb_sample[blk][ch][0] +
-  ff_synmatrix4[i][1] * frame->sb_sample[blk][ch][1] +
-  ff_synmatrix4[i][2] * frame->sb_sample[blk][ch][2] +
-  ff_synmatrix4[i][3] * frame->sb_sample[blk][ch][3] ) >> 15;
+(int)( (unsigned)ff_synmatrix4[i][0] * 
frame->sb_sample[blk][ch][0] +
+   (unsigned)ff_synmatrix4[i][1] * 
frame->sb_sample[blk][ch][1] +
+   (unsigned)ff_synmatrix4[i][2] * 
frame->sb_sample[blk][ch][2] +
+   (unsigned)ff_synmatrix4[i][3] * 
frame->sb_sample[blk][ch][3] ) >> 15;
 }
 
 /* Compute the samples */
@@ -239,16 +239,16 @@ static inline void sbc_synthesize_four(struct 
sbc_decoder_state *state,
 
 /* Store in output, Q0 */
 AV_WN16A(&output_frame->data[ch][blk * 8 + i * 2], av_clip_int16(
-( v[offset[i] + 0] * ff_sbc_proto_4_40m0[idx + 0] +
-  v[offset[k] + 1] * ff_sbc_proto_4_40m1[idx + 0] +
-  v[offset[i] + 2] * ff_sbc_proto_4_40m0[idx + 1] +
-  v[offset[k] + 3] * ff_sbc_proto_4_40m1[idx + 1] +
-  v[offset[i] + 4] * ff_sbc_proto_4_40m0[idx + 2] +
-  v[offset[k] + 5] * ff_sbc_proto_4_40m1[idx + 2] +
-  v[offset[i] + 6] * ff_sbc_proto_4_40m0[idx + 3] +
-  v[offset[k] + 7] * ff_sbc_proto_4_40m1[idx + 3] +
-  v[offset[i] + 8] * ff_sbc_proto_4_40m0[idx + 4] +
-  v[offset[k] + 9] * ff_sbc_proto_4_40m1[idx + 4] ) >> 15));
+ (int)( (unsigned)v[offset[i] + 0] * ff_sbc_proto_4_40m0[idx + 0] +
+(unsigned)v[offset[k] + 1] * ff_sbc_proto_4_40m1[idx + 0] +
+(unsigned)v[offset[i] + 2] * ff_sbc_proto_4_40m0[idx + 1] +
+(unsigned)v[offset[k] + 3] * ff_sbc_proto_4_40m1[idx + 1] +
+(unsigned)v[offset[i] + 4] * ff_sbc_proto_4_40m0[idx + 2] +
+(unsigned)v[offset[k] + 5] * ff_sbc_proto_4_40m1[idx + 2] +
+(unsigned)v[offset[i] + 6] * ff_sbc_proto_4_40m0[idx + 3] +
+(unsigned)v[offset[k] + 7] * ff_sbc_proto_4_40m1[idx + 3] +
+(unsigned)v[offset[i] + 8] * ff_sbc_proto_4_40m0[idx + 4] +
+(unsigned)v[offset[k] + 9] * ff_sbc_proto_4_40m1[idx + 4] ) >> 
15));
 }
 }
 
-- 
2.23.0

___
ffmpeg-devel mailing list
ffmpeg-devel@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-devel

To unsubscribe, visit link above, or email
ffmpeg-devel-requ...@ffmpeg.org with subject "unsubscribe".