avcodec/cook: bound subpacket channel sum against channel count

Fixes: out of array read
Fixes: evil.rm

Found-by: Anthropic agents; validated and reported by Ada Logics.

Signed-off-by: David Korczynski <david@adalogics.com>
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 1152139b48)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
David Korczynski
2026-05-21 04:30:36 -07:00
committed by Michael Niedermayer
parent af81aaae76
commit 0bbf29dee3
+5 -2
View File
@@ -1080,6 +1080,7 @@ static av_cold int cook_decode_init(AVCodecContext *avctx)
int s = 0;
unsigned int channel_mask = 0;
int samples_per_frame = 0;
int total_channels = 0;
int ret;
int channels = avctx->ch_layout.nb_channels;
@@ -1237,10 +1238,12 @@ static av_cold int cook_decode_init(AVCodecContext *avctx)
q->subpacket[s].gains2.now = q->subpacket[s].gain_3;
q->subpacket[s].gains2.previous = q->subpacket[s].gain_4;
if (q->num_subpackets + q->subpacket[s].num_channels > channels) {
av_log(avctx, AV_LOG_ERROR, "Too many subpackets %d for channels %d\n", q->num_subpackets, channels);
if (total_channels + q->subpacket[s].num_channels > channels) {
av_log(avctx, AV_LOG_ERROR, "Too many subpacket channels %d for channels %d\n",
total_channels + q->subpacket[s].num_channels, channels);
return AVERROR_INVALIDDATA;
}
total_channels += q->subpacket[s].num_channels;
q->num_subpackets++;
s++;