avcodec/h264_slice: Clear ref_counts on redundant slices
authorMichael Niedermayer <michael@niedermayer.cc>
Wed, 8 Feb 2017 16:55:41 +0000 (17:55 +0100)
committerMichael Niedermayer <michael@niedermayer.cc>
Wed, 8 Feb 2017 19:08:22 +0000 (20:08 +0100)
Fixes reading freed memory
Fixes: 568/clusterfuzz-testcase-6107186067406848

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit c03029a835949fc0e68b4c6558ebcdc3ae137087)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
libavcodec/h264.c

index b979b15..550a7fc 100644 (file)
@@ -1591,7 +1591,9 @@ again:
 #endif
                     } else
                         context_count++;
-                }
+                } else
+                    sl->ref_count[0] = sl->ref_count[1] = 0;
+            break;
                 break;
             case NAL_DPA:
             case NAL_DPB: