mvc: added check for incorrect pocs in DPB list

Bug: 250317489
Test: fuzzer poc in bug
Change-Id: I4defa4c3f58d3131893e694ba125b5e1a76e71ad
This commit is contained in:
Ashwin Natesan 2022-10-06 15:22:16 +05:30
parent 7e9911f8e0
commit d813b95df7
No known key found for this signature in database
GPG key ID: F9C8103B9094CF1A
3 changed files with 33 additions and 0 deletions

View file

@ -25,6 +25,7 @@
/* Description : Functions for MVC NALU parsing */
/* */
/*****************************************************************************/
#include <stdbool.h>
#include "ih264_typedefs.h"
#include "ih264d_error_handler.h"
@ -2176,3 +2177,27 @@ WORD32 imvcd_dpb_update_default_index_list(mvc_dpb_manager_t *ps_dpb_mgr)
return OK;
}
bool imvcd_dpb_is_diff_poc_valid(mvc_dpb_manager_t *ps_dpb_mgr, WORD32 i4_curr_poc)
{
WORD32 i;
mvc_dpb_info_t *ps_next_dpb = ps_dpb_mgr->ps_dpb_st_head;
/* Check in conformance with section 8.2.1 from spec */
/* Particularly the statement - */
/* 'The bitstream shall not contain data that result in values of DiffPicOrderCnt(picA, picB)
* used in the decoding process that exceed the range of -2^15 to 2^15 - 1 inclusive' */
for(i = 0; i < ps_dpb_mgr->u1_num_st_ref_bufs; i++)
{
if(((((WORD64) i4_curr_poc) - ((WORD64) ps_next_dpb->ps_au_buf->i4_poc)) >= (1 << 15)) ||
((((WORD64) i4_curr_poc) - ((WORD64) ps_next_dpb->ps_au_buf->i4_poc)) < -(1 << 15)))
{
return false;
}
ps_next_dpb = ps_next_dpb->ps_prev_short;
}
return true;
}

View file

@ -28,6 +28,7 @@
#ifndef _IMVCD_DPB_MANAGER_H_
#define _IMVCD_DPB_MANAGER_H_
#include <stdbool.h>
#include <string.h>
#include "ih264_typedefs.h"
@ -214,4 +215,6 @@ extern pic_buffer_t **imvcd_dpb_get_view_ref_pic_list(mvc_dpb_manager_t *ps_dpb_
UWORD16 u2_view_order_id, UWORD16 u2_view_id,
UWORD8 u1_pred_dir);
extern bool imvcd_dpb_is_diff_poc_valid(mvc_dpb_manager_t *ps_dpb_mgr, WORD32 i4_curr_poc);
#endif

View file

@ -2242,6 +2242,11 @@ WORD32 imvcd_parse_decode_slice(mvc_dec_ctxt_t *ps_mvcd_ctxt)
}
}
if(!imvcd_dpb_is_diff_poc_valid(ps_mvcd_ctxt->ps_dpb_mgr, ps_cur_slice->i4_poc))
{
return ERROR_INV_SLICE_HDR_T;
}
if(ps_view_ctxt->u1_separate_parse == 1)
{
if(!ps_view_ctxt->u4_dec_thread_created)