Fix for Heap-buffer-overflow WRITE 8 in ixheaacd_init_sbr

These changes handle the Heap-buffer-overflow WRITE 8 runtime error reported
due to unsupported channel configuration for USAC.

Bug: ossFuzz:64960
Test: poc in bug
This commit is contained in:
Shashank Pathmudi 2023-12-18 16:04:32 +05:30
parent b5c3233a7a
commit 2624ae15b4
2 changed files with 8 additions and 0 deletions

View file

@ -535,6 +535,11 @@ WORD32 ixheaacd_ga_hdr_dec(ia_aac_dec_state_struct *aac_state_struct,
aac_state_struct->ch_config = ixheaacd_read_bits_buf(it_bit_buff, 4);
if (aac_state_struct->audio_object_type == AOT_USAC &&
((aac_state_struct->ch_config >= 3) && (aac_state_struct->ch_config != 8))) {
return IA_XHEAAC_DEC_INIT_FATAL_DEC_INIT_FAIL;
}
pstr_audio_specific_config->channel_configuration =
aac_state_struct->ch_config;

View file

@ -644,6 +644,9 @@ WORD32 ixheaacd_config(ia_bit_buf_struct *it_bit_buff, ia_usac_config_struct *ps
if (BS_MAX_NUM_OUT_CHANNELS < pstr_usac_conf->num_out_channels) {
return IA_XHEAAC_DEC_INIT_FATAL_STREAM_CHAN_GT_MAX;
}
if (pstr_usac_conf->num_out_channels < 1) {
return IA_XHEAAC_DEC_INIT_FATAL_DEC_INIT_FAIL;
}
for (i = 0; i < pstr_usac_conf->num_out_channels; i++)
pstr_usac_conf->output_channel_pos[i] =
ixheaacd_read_bits_buf(it_bit_buff, 5);