From: Anton Khirnov Date: Thu, 28 Nov 2013 09:54:35 +0000 (+0100) Subject: h264: reset ref count if decoding the slice header fails X-Git-Tag: android-x86-6.0-r1~10^2~2326 X-Git-Url: http://git.osdn.net/view?a=commitdiff_plain;h=0652e024c680420d298cdf3719d0a0c030173fe3;p=android-x86%2Fexternal-ffmpeg.git h264: reset ref count if decoding the slice header fails Otherwise the ER code might try to use some already freed references. Fixes possible access to freed memory. Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind CC:libav-stable@libav.org --- diff --git a/libavcodec/h264.c b/libavcodec/h264.c index ed5aea8e1a..6f329aacb3 100644 --- a/libavcodec/h264.c +++ b/libavcodec/h264.c @@ -4813,9 +4813,10 @@ again: context_count = 0; } - if (err < 0) + if (err < 0) { av_log(h->avctx, AV_LOG_ERROR, "decode_slice_header error\n"); - else if (err == 1) { + h->ref_count[0] = h->ref_count[1] = h->list_count = 0; + } else if (err == 1) { /* Slice could not be decoded in parallel mode, copy down * NAL unit stuff to context 0 and restart. Note that * rbsp_buffer is not transferred, but since we no longer