[FFmpeg-cvslog] h264: reset ref count if decoding the slice header fails
Anton Khirnov
git at videolan.org
Sat Jan 18 22:57:41 CET 2014
ffmpeg | branch: master | Anton Khirnov <anton at khirnov.net> | Thu Nov 28 10:54:35 2013 +0100| [0652e024c680420d298cdf3719d0a0c030173fe3] | committer: Anton Khirnov
h264: reset ref count if decoding the slice header fails
Otherwise the ER code might try to use some already freed references.
Fixes possible access to freed memory.
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
CC:libav-stable at libav.org
> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=0652e024c680420d298cdf3719d0a0c030173fe3
---
libavcodec/h264.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/libavcodec/h264.c b/libavcodec/h264.c
index ed5aea8..6f329aa 100644
--- a/libavcodec/h264.c
+++ b/libavcodec/h264.c
@@ -4813,9 +4813,10 @@ again:
context_count = 0;
}
- if (err < 0)
+ if (err < 0) {
av_log(h->avctx, AV_LOG_ERROR, "decode_slice_header error\n");
- else if (err == 1) {
+ h->ref_count[0] = h->ref_count[1] = h->list_count = 0;
+ } else if (err == 1) {
/* Slice could not be decoded in parallel mode, copy down
* NAL unit stuff to context 0 and restart. Note that
* rbsp_buffer is not transferred, but since we no longer
More information about the ffmpeg-cvslog
mailing list