Skip to content

Use of uninitialised value in dav1d_loopfilter_sbrow_16bpc() src/lf_apply_tmpl.c

Reproduced with commit c0351e1b

Steps to reproduce:

  1. build dav1d with CFLAGS="-Og -g"
  2. replay testcase with valgrind -q ./dav1d_fuzzer testcase.ivf

testcase.ivf

Use of uninitialised value of size 8
   at 0x16C90E: dav1d_loopfilter_sbrow_16bpc (lf_apply_tmpl.c:225)
   by 0x1509CB: dav1d_filter_sbrow_16bpc (recon_tmpl.c:1459)
   by 0x11B3D3: dav1d_decode_frame (decode.c:2673)
   by 0x11C5D5: dav1d_submit_frame (decode.c:3040)
   by 0x10EFA3: dav1d_parse_obus (obu.c:1137)
   by 0x10B2AB: dav1d_decode (lib.c:201)
   by 0x109E40: LLVMFuzzerTestOneInput (dav1d_fuzzer.c:101)
   by 0x109FE5: main (main.c:112)
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information