Skip to content
Snippets Groups Projects
Commit 164758a8 authored by Michael Niedermayer's avatar Michael Niedermayer
Browse files

tools/target_dec_fuzzer: Fuzz video decoder related fields in context.


Signed-off-by: default avatarMichael Niedermayer <michael@niedermayer.cc>
parent c6aaf084
No related branches found
No related tags found
No related merge requests found
...@@ -49,6 +49,7 @@ ...@@ -49,6 +49,7 @@
#include "libavutil/intreadwrite.h" #include "libavutil/intreadwrite.h"
#include "libavcodec/avcodec.h" #include "libavcodec/avcodec.h"
#include "libavcodec/bytestream.h"
#include "libavformat/avformat.h" #include "libavformat/avformat.h"
static void error(const char *err) static void error(const char *err)
...@@ -151,6 +152,18 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { ...@@ -151,6 +152,18 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
ctx->max_pixels = 4096 * 4096; //To reduce false positive OOM and hangs ctx->max_pixels = 4096 * 4096; //To reduce false positive OOM and hangs
if (size > 1024) {
GetByteContext gbc;
bytestream2_init(&gbc, data + size - 1024, 1024);
ctx->width = bytestream2_get_le32(&gbc);
ctx->height = bytestream2_get_le32(&gbc);
ctx->bit_rate = bytestream2_get_le64(&gbc);
ctx->bits_per_coded_sample = bytestream2_get_le32(&gbc);
if (av_image_check_size(ctx->width, ctx->height, 0, ctx))
ctx->width = ctx->height = 0;
size -= 1024;
}
int res = avcodec_open2(ctx, c, NULL); int res = avcodec_open2(ctx, c, NULL);
if (res < 0) if (res < 0)
return res; return res;
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment