avcodec/pngdec: Clean up on av_frame_ref() failure
authorMichael Niedermayer <michael@niedermayer.cc>
Sun, 17 Sep 2017 00:42:11 +0000 (02:42 +0200)
committerMichael Niedermayer <michael@niedermayer.cc>
Wed, 31 Jan 2018 21:56:14 +0000 (22:56 +0100)
Fixes: memleak
Fixes: 3203/clusterfuzz-testcase-minimized-4514553595428864

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Reviewed-by: James Almer <jamrial@gmail.com>
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 5480e82d77770e81e897a8c217f3c7f0c13a6de1)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
libavcodec/pngdec.c

index ba1b39e..ac49954 100644 (file)
@@ -1303,7 +1303,7 @@ static int decode_frame_png(AVCodecContext *avctx,
         goto the_end;
 
     if ((ret = av_frame_ref(data, s->picture.f)) < 0)
-        return ret;
+        goto the_end;
 
     *got_frame = 1;