Commit 761362ff authored by Michael Niedermayer's avatar Michael Niedermayer

avcodec/h264_slice: Do not attempt to render into frames already output

Fixes: null pointer dereference
Fixes: 4698/clusterfuzz-testcase-minimized-5096956322906112

This testcase does not reproduce the issue before 03b82b3a

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpegSigned-off-by: 's avatarMichael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 476665d4)
Signed-off-by: 's avatarMichael Niedermayer <michael@niedermayer.cc>
parent 0abf465d
...@@ -1634,6 +1634,12 @@ int ff_h264_decode_slice_header(H264Context *h, H264SliceContext *sl) ...@@ -1634,6 +1634,12 @@ int ff_h264_decode_slice_header(H264Context *h, H264SliceContext *sl)
h->missing_fields ++; h->missing_fields ++;
h->cur_pic_ptr = NULL; h->cur_pic_ptr = NULL;
h->first_field = FIELD_PICTURE(h); h->first_field = FIELD_PICTURE(h);
} else if (h->cur_pic_ptr->reference & DELAYED_PIC_REF) {
/* This frame was already output, we cannot draw into it
* anymore.
*/
h->first_field = 1;
h->cur_pic_ptr = NULL;
} else { } else {
h->missing_fields = 0; h->missing_fields = 0;
if (h->cur_pic_ptr->frame_num != h->frame_num) { if (h->cur_pic_ptr->frame_num != h->frame_num) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment