rmdemux: Check for integer overflow when calculation audio packet size

Fixes ZDI-CAN-21444
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/2782

Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5072>
This commit is contained in:
Sebastian Dröge 2023-07-07 10:08:21 +03:00 committed by GStreamer Marge Bot
parent d8d83ad435
commit 67e38cf47b

View file

@ -2007,6 +2007,7 @@ gst_rmdemux_descramble_audio (GstRMDemux * rmdemux, GstRMDemuxStream * stream)
guint packet_size = stream->packet_size; guint packet_size = stream->packet_size;
guint height = stream->subpackets->len; guint height = stream->subpackets->len;
guint leaf_size = stream->leaf_size; guint leaf_size = stream->leaf_size;
guint size;
guint p, x; guint p, x;
g_assert (stream->height == height); g_assert (stream->height == height);
@ -2014,7 +2015,12 @@ gst_rmdemux_descramble_audio (GstRMDemux * rmdemux, GstRMDemuxStream * stream)
GST_LOG_OBJECT (rmdemux, "packet_size = %u, leaf_size = %u, height= %u", GST_LOG_OBJECT (rmdemux, "packet_size = %u, leaf_size = %u, height= %u",
packet_size, leaf_size, height); packet_size, leaf_size, height);
outbuf = gst_buffer_new_and_alloc (height * packet_size); if (!g_uint_checked_mul (&size, height, packet_size)) {
GST_ERROR_OBJECT (rmdemux, "overflowing audio packet size");
return GST_FLOW_ERROR;
}
outbuf = gst_buffer_new_and_alloc (size);
gst_buffer_map (outbuf, &outmap, GST_MAP_WRITE); gst_buffer_map (outbuf, &outmap, GST_MAP_WRITE);
for (p = 0; p < height; ++p) { for (p = 0; p < height; ++p) {