From d813b95df761fb7a6a5a379614d14e5f01d861db Mon Sep 17 00:00:00 2001 From: Ashwin Natesan Date: Thu, 6 Oct 2022 15:22:16 +0530 Subject: [PATCH] mvc: added check for incorrect pocs in DPB list Bug: 250317489 Test: fuzzer poc in bug Change-Id: I4defa4c3f58d3131893e694ba125b5e1a76e71ad --- decoder/mvc/imvcd_dpb_manager.c | 25 +++++++++++++++++++++++++ decoder/mvc/imvcd_dpb_manager.h | 3 +++ decoder/mvc/imvcd_slice_functions.c | 5 +++++ 3 files changed, 33 insertions(+) diff --git a/decoder/mvc/imvcd_dpb_manager.c b/decoder/mvc/imvcd_dpb_manager.c index 31da6a9..b05a123 100644 --- a/decoder/mvc/imvcd_dpb_manager.c +++ b/decoder/mvc/imvcd_dpb_manager.c @@ -25,6 +25,7 @@ /* Description : Functions for MVC NALU parsing */ /* */ /*****************************************************************************/ +#include #include "ih264_typedefs.h" #include "ih264d_error_handler.h" @@ -2176,3 +2177,27 @@ WORD32 imvcd_dpb_update_default_index_list(mvc_dpb_manager_t *ps_dpb_mgr) return OK; } + +bool imvcd_dpb_is_diff_poc_valid(mvc_dpb_manager_t *ps_dpb_mgr, WORD32 i4_curr_poc) +{ + WORD32 i; + + mvc_dpb_info_t *ps_next_dpb = ps_dpb_mgr->ps_dpb_st_head; + + /* Check in conformance with section 8.2.1 from spec */ + /* Particularly the statement - */ + /* 'The bitstream shall not contain data that result in values of DiffPicOrderCnt(picA, picB) + * used in the decoding process that exceed the range of -2^15 to 2^15 - 1 inclusive' */ + for(i = 0; i < ps_dpb_mgr->u1_num_st_ref_bufs; i++) + { + if(((((WORD64) i4_curr_poc) - ((WORD64) ps_next_dpb->ps_au_buf->i4_poc)) >= (1 << 15)) || + ((((WORD64) i4_curr_poc) - ((WORD64) ps_next_dpb->ps_au_buf->i4_poc)) < -(1 << 15))) + { + return false; + } + + ps_next_dpb = ps_next_dpb->ps_prev_short; + } + + return true; +} diff --git a/decoder/mvc/imvcd_dpb_manager.h b/decoder/mvc/imvcd_dpb_manager.h index 0c3d914..d9757cf 100644 --- a/decoder/mvc/imvcd_dpb_manager.h +++ b/decoder/mvc/imvcd_dpb_manager.h @@ -28,6 +28,7 @@ #ifndef _IMVCD_DPB_MANAGER_H_ #define _IMVCD_DPB_MANAGER_H_ +#include #include #include "ih264_typedefs.h" @@ -214,4 +215,6 @@ extern pic_buffer_t **imvcd_dpb_get_view_ref_pic_list(mvc_dpb_manager_t *ps_dpb_ UWORD16 u2_view_order_id, UWORD16 u2_view_id, UWORD8 u1_pred_dir); +extern bool imvcd_dpb_is_diff_poc_valid(mvc_dpb_manager_t *ps_dpb_mgr, WORD32 i4_curr_poc); + #endif diff --git a/decoder/mvc/imvcd_slice_functions.c b/decoder/mvc/imvcd_slice_functions.c index ae1de9d..e44f2a5 100644 --- a/decoder/mvc/imvcd_slice_functions.c +++ b/decoder/mvc/imvcd_slice_functions.c @@ -2242,6 +2242,11 @@ WORD32 imvcd_parse_decode_slice(mvc_dec_ctxt_t *ps_mvcd_ctxt) } } + if(!imvcd_dpb_is_diff_poc_valid(ps_mvcd_ctxt->ps_dpb_mgr, ps_cur_slice->i4_poc)) + { + return ERROR_INV_SLICE_HDR_T; + } + if(ps_view_ctxt->u1_separate_parse == 1) { if(!ps_view_ctxt->u4_dec_thread_created)