PR #20878 opened by michaelni URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20878 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20878.patch
Fixes: use of uninitialized memory Fixes: 418335931/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_RV60_fuzzer-5103986067963904 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <[email protected]> >From fcc23a774c8d1a3d77f9ea60a04572587d7f6146 Mon Sep 17 00:00:00 2001 From: Michael Niedermayer <[email protected]> Date: Sun, 9 Nov 2025 16:03:32 +0100 Subject: [PATCH] avcodec/rv60dec: Clear blk_info Fixes: use of uninitialized memory Fixes: 418335931/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_RV60_fuzzer-5103986067963904 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <[email protected]> --- libavcodec/rv60dec.c | 1 + 1 file changed, 1 insertion(+) diff --git a/libavcodec/rv60dec.c b/libavcodec/rv60dec.c index b7b4f46512..76caa6a361 100644 --- a/libavcodec/rv60dec.c +++ b/libavcodec/rv60dec.c @@ -311,6 +311,7 @@ static int update_dimensions_clear_info(RV60Context *s, int width, int height) return ret; memset(s->pu_info, 0, s->pu_stride * (s->cu_height << 3) * sizeof(s->pu_info[0])); + memset(s->blk_info, 0, s->blk_stride * (s->cu_height << 4) * sizeof(s->blk_info[0])); for (int j = 0; j < s->cu_height << 4; j++) for (int i = 0; i < s->cu_width << 4; i++) -- 2.49.1 _______________________________________________ ffmpeg-devel mailing list -- [email protected] To unsubscribe send an email to [email protected]
