diff options
author | Sebastian Dröge <sebastian@centricular.com> | 2023-07-07 09:59:20 +0300 |
---|---|---|
committer | GStreamer Marge Bot <gitlab-merge-bot@gstreamer-foundation.org> | 2023-07-19 13:13:45 +0000 |
commit | 4266ba0fd2be7702044a5d90a8215abe41709874 (patch) | |
tree | 5b61d435fb8caaba6cca8ce2caf241cbaa42e353 | |
parent | 6e61b944a4066d8e3662c26b0ae76032efb5f236 (diff) |
rmdemux: Check for integer overflows when calculating the size of SIPR audio buffers
Fixes ZDI-CAN-21443
Fixes https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/2782
Part-of: <https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5073>
-rw-r--r-- | subprojects/gst-plugins-ugly/gst/realmedia/rmdemux.c | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/subprojects/gst-plugins-ugly/gst/realmedia/rmdemux.c b/subprojects/gst-plugins-ugly/gst/realmedia/rmdemux.c index 473aebe075..eaee9acdd1 100644 --- a/subprojects/gst-plugins-ugly/gst/realmedia/rmdemux.c +++ b/subprojects/gst-plugins-ugly/gst/realmedia/rmdemux.c @@ -2144,6 +2144,7 @@ gst_rmdemux_descramble_sipr_audio (GstRMDemux * rmdemux, GstMapInfo outmap; guint packet_size = stream->packet_size; guint height = stream->subpackets->len; + guint size; guint p; g_assert (stream->height == height); @@ -2151,7 +2152,12 @@ gst_rmdemux_descramble_sipr_audio (GstRMDemux * rmdemux, GST_LOG_OBJECT (rmdemux, "packet_size = %u, leaf_size = %u, height= %u", packet_size, stream->leaf_size, height); - outbuf = gst_buffer_new_and_alloc (height * packet_size); + if (!g_uint_checked_mul (&size, height, packet_size)) { + GST_ERROR_OBJECT (rmdemux, "overflowing SIPR audio packet size"); + return GST_FLOW_ERROR; + } + + outbuf = gst_buffer_new_and_alloc (size); gst_buffer_map (outbuf, &outmap, GST_MAP_WRITE); for (p = 0; p < height; ++p) { |