This is an automated email from the git hooks/post-receive script.

Git pushed a commit to branch release/6.1
in repository ffmpeg.

commit 52d9196ab22235183e24a815f3ecd8b79066ffac
Author:     Michael Niedermayer <[email protected]>
AuthorDate: Sat Jun 20 14:39:41 2026 +0200
Commit:     Michael Niedermayer <[email protected]>
CommitDate: Sat Jun 20 17:42:28 2026 +0200

    avcodec/hevc/hevcdec: Clean sao_pixel_buffer_v on allocation
    
    Fixes: use of uninitialized memory
    Fixes: 
378102648/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5896308499480576
    
    Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
    Signed-off-by: Michael Niedermayer <[email protected]>
    (cherry picked from commit 7a21c37f75ef493bafed3e3fdfbd3cf48990439b)
    Signed-off-by: Michael Niedermayer <[email protected]>
---
 libavcodec/hevcdec.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/libavcodec/hevcdec.c b/libavcodec/hevcdec.c
index cf41e2435d..25b33903e2 100644
--- a/libavcodec/hevcdec.c
+++ b/libavcodec/hevcdec.c
@@ -559,10 +559,10 @@ static int set_sps(HEVCContext *s, const HEVCSPS *sps,
             int w = sps->width >> sps->hshift[c_idx];
             int h = sps->height >> sps->vshift[c_idx];
             s->sao_pixel_buffer_h[c_idx] =
-                av_malloc((w * 2 * sps->ctb_height) <<
+                av_mallocz((w * 2 * sps->ctb_height) <<
                           sps->pixel_shift);
             s->sao_pixel_buffer_v[c_idx] =
-                av_malloc((h * 2 * sps->ctb_width) <<
+                av_mallocz((h * 2 * sps->ctb_width) <<
                           sps->pixel_shift);
             if (!s->sao_pixel_buffer_h[c_idx] ||
                 !s->sao_pixel_buffer_v[c_idx])

_______________________________________________
ffmpeg-cvslog mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to