Fix for Heap-buffer-overflow in Codec__decodeXAACStream (#85)
These changes fix the Heap-buffer-overflow in Codec__decodeXAACStream runtime error caused due to unsupported frame length type configuration for LATM streams. Bug: ossFuzz:67767 Test: poc in bug
This commit is contained in:
parent
da04d9de78
commit
12e2e71b24
3 changed files with 14 additions and 15 deletions
|
|
@ -1127,19 +1127,12 @@ WORD32 ixheaacd_aac_headerdecode(
|
|||
ixheaacd_latm_header_decode(aac_state_struct, &it_bit_buff,
|
||||
bytes_consumed, pstr_samp_rate_info);
|
||||
if (result != 0) {
|
||||
if ((result ==
|
||||
(WORD32)
|
||||
IA_XHEAAC_DEC_EXE_NONFATAL_INSUFFICIENT_INPUT_BYTES) ||
|
||||
(result ==
|
||||
(WORD32)IA_XHEAAC_DEC_INIT_FATAL_STREAM_CHAN_GT_MAX)) {
|
||||
if ((result == (WORD32)IA_XHEAAC_DEC_EXE_NONFATAL_INSUFFICIENT_INPUT_BYTES) ||
|
||||
(result < 0)) {
|
||||
bytes_taken += *bytes_consumed;
|
||||
*bytes_consumed = bytes_taken;
|
||||
return result;
|
||||
} else if (result == -1)
|
||||
return -1;
|
||||
else if (result == (WORD32)IA_FATAL_ERROR)
|
||||
return IA_FATAL_ERROR;
|
||||
else
|
||||
} else
|
||||
bytes_taken += *bytes_consumed - 1;
|
||||
continue;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -253,6 +253,8 @@ IA_ERRORCODE ixheaacd_latm_stream_mux_config(
|
|||
}
|
||||
break;
|
||||
|
||||
case 1:
|
||||
latm_element->frame_length = ixheaacd_read_bits_buf(it_bit_buff, 9);
|
||||
default:
|
||||
return IA_XHEAAC_DEC_EXE_FATAL_INVALID_LOAS_HEADER;
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue