From 17e36fac0b5432f67e25adca7186c57f2dbe1c71 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Sun, 10 Oct 2021 23:13:43 +0200 Subject: [PATCH] avcodec/utils: Ensure 8x8 alignment for ARGO in avcodec_align_dimensions2() Fixes: out of array access Fixes: 39736/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ARGO_fuzzer-4820016722214912 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer --- libavcodec/utils.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/libavcodec/utils.c b/libavcodec/utils.c index b4076d94f2..a91a54b0dc 100644 --- a/libavcodec/utils.c +++ b/libavcodec/utils.c @@ -270,6 +270,7 @@ void avcodec_align_dimensions2(AVCodecContext *s, int *width, int *height, h_align = 4; } if (s->codec_id == AV_CODEC_ID_JV || + s->codec_id == AV_CODEC_ID_ARGO || s->codec_id == AV_CODEC_ID_INTERPLAY_VIDEO) { w_align = 8; h_align = 8; @@ -300,8 +301,8 @@ void avcodec_align_dimensions2(AVCodecContext *s, int *width, int *height, break; case AV_PIX_FMT_BGR0: if (s->codec_id == AV_CODEC_ID_ARGO) { - w_align = 4; - h_align = 4; + w_align = 8; + h_align = 8; } break; default: