Fix for Heap-buffer-overflow in Codec__decodeXAACStream (#85)

These changes fix the Heap-buffer-overflow in Codec__decodeXAACStream runtime error
caused due to unsupported frame length type configuration for LATM streams.

Bug: ossFuzz:67767
Test: poc in bug
This commit is contained in:
ShashankPathmudi 2024-04-16 17:58:40 +05:30 • committed by GitHub
parent da04d9de78
commit 12e2e71b24
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 14 additions and 15 deletions

View file

@ -1127,19 +1127,12 @@ WORD32 ixheaacd_aac_headerdecode(
ixheaacd_latm_header_decode(aac_state_struct, &it_bit_buff,
bytes_consumed, pstr_samp_rate_info);
if (result != 0) {
if ((result ==
(WORD32)
IA_XHEAAC_DEC_EXE_NONFATAL_INSUFFICIENT_INPUT_BYTES) ||
(result ==
(WORD32)IA_XHEAAC_DEC_INIT_FATAL_STREAM_CHAN_GT_MAX)) {
if ((result == (WORD32)IA_XHEAAC_DEC_EXE_NONFATAL_INSUFFICIENT_INPUT_BYTES) ||
(result < 0)) {
bytes_taken += *bytes_consumed;
*bytes_consumed = bytes_taken;
return result;
} else if (result == -1)
return -1;
else if (result == (WORD32)IA_FATAL_ERROR)
return IA_FATAL_ERROR;
else
} else
bytes_taken += *bytes_consumed - 1;
continue;
}

View file

@ -253,6 +253,8 @@ IA_ERRORCODE ixheaacd_latm_stream_mux_config(
}
break;
case 1:
latm_element->frame_length = ixheaacd_read_bits_buf(it_bit_buff, 9);
default:
return IA_XHEAAC_DEC_EXE_FATAL_INVALID_LOAS_HEADER;
}