mirror of
https://gitlab.freedesktop.org/gstreamer/gstreamer.git
synced 2025-01-08 16:35:40 +00:00
rmdemux: Check for integer overflow when calculation audio packet size
Fixes ZDI-CAN-21444 https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/2782 Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5072>
This commit is contained in:
parent
d8d83ad435
commit
67e38cf47b
1 changed files with 7 additions and 1 deletions
|
@ -2007,6 +2007,7 @@ gst_rmdemux_descramble_audio (GstRMDemux * rmdemux, GstRMDemuxStream * stream)
|
||||||
guint packet_size = stream->packet_size;
|
guint packet_size = stream->packet_size;
|
||||||
guint height = stream->subpackets->len;
|
guint height = stream->subpackets->len;
|
||||||
guint leaf_size = stream->leaf_size;
|
guint leaf_size = stream->leaf_size;
|
||||||
|
guint size;
|
||||||
guint p, x;
|
guint p, x;
|
||||||
|
|
||||||
g_assert (stream->height == height);
|
g_assert (stream->height == height);
|
||||||
|
@ -2014,7 +2015,12 @@ gst_rmdemux_descramble_audio (GstRMDemux * rmdemux, GstRMDemuxStream * stream)
|
||||||
GST_LOG_OBJECT (rmdemux, "packet_size = %u, leaf_size = %u, height= %u",
|
GST_LOG_OBJECT (rmdemux, "packet_size = %u, leaf_size = %u, height= %u",
|
||||||
packet_size, leaf_size, height);
|
packet_size, leaf_size, height);
|
||||||
|
|
||||||
outbuf = gst_buffer_new_and_alloc (height * packet_size);
|
if (!g_uint_checked_mul (&size, height, packet_size)) {
|
||||||
|
GST_ERROR_OBJECT (rmdemux, "overflowing audio packet size");
|
||||||
|
return GST_FLOW_ERROR;
|
||||||
|
}
|
||||||
|
|
||||||
|
outbuf = gst_buffer_new_and_alloc (size);
|
||||||
gst_buffer_map (outbuf, &outmap, GST_MAP_WRITE);
|
gst_buffer_map (outbuf, &outmap, GST_MAP_WRITE);
|
||||||
|
|
||||||
for (p = 0; p < height; ++p) {
|
for (p = 0; p < height; ++p) {
|
||||||
|
|
Loading…
Reference in a new issue