Validate dimensions and crop offsets in H.264 SPS parser

Add bounds checking in SpsParser to prevent arithmetic overflow and
underflow when calculating picture dimensions and crop offsets:
- Validate chroma_format_idc (<= 3) and pic_order_cnt_type (<= 2).
- Compute uncropped dimensions using 64-bit arithmetic and verify
  they do not exceed uint16_t limits.
- Ensure total crop offsets do not equal or exceed uncropped dimensions,
  preventing underflow and zero or negative picture sizes.
- Return std::nullopt on malformed parameters.

Bug: chromium:516683896
Change-Id: Ib405c094f9d7b568f436033bd356039ace1104df
Reviewed-on: https://webrtc-review.googlesource.com/c/src/+/500603
Reviewed-by: Sergey Silkin <ssilkin@webrtc.org>
Commit-Queue: Erik Språng <sprang@webrtc.org>
Cr-Commit-Position: refs/heads/main@{#48515}
6 files changed
tree: abdafbb83f135d85d3feee8d671165776429de7b
  1. .agents/
  2. agents/
  3. api/
  4. audio/
  5. build_overrides/
  6. call/
  7. common_audio/
  8. common_video/
  9. data/
  10. docs/
  11. examples/
  12. experiments/
  13. g3doc/
  14. infra/
  15. logging/
  16. media/
  17. modules/
  18. net/
  19. p2p/
  20. pc/
  21. resources/
  22. rtc_base/
  23. rtc_tools/
  24. rust/
  25. sdk/
  26. stats/
  27. system_wrappers/
  28. test/
  29. tools_webrtc/
  30. video/
  31. .clang-format
  32. .clang-tidy
  33. .git-blame-ignore-revs
  34. .gitignore
  35. .gn
  36. .mailmap
  37. .rustfmt.toml
  38. .style.mdformat
  39. .style.yapf
  40. .vpython3
  41. .yapfignore
  42. AUTHORS
  43. BUILD.gn
  44. CODE_OF_CONDUCT.md
  45. codereview.settings
  46. DEPS
  47. DIR_METADATA
  48. ENG_REVIEW_OWNERS
  49. GEMINI.md
  50. LICENSE
  51. license_template.txt
  52. native-api.md
  53. OWNERS
  54. OWNERS_INFRA
  55. PATENTS
  56. PRESUBMIT.py
  57. presubmit_test.py
  58. presubmit_test_mocks.py
  59. pylintrc
  60. pylintrc_old_style
  61. README.chromium
  62. README.md
  63. unsafe_buffers_paths.txt
  64. WATCHLISTS
  65. webrtc.gni
  66. webrtc_lib_link_test.cc
  67. whitespace.txt
README.md

WebRTC is a free, open software project that provides browsers and mobile applications with Real-Time Communications (RTC) capabilities via simple APIs. The WebRTC components have been optimized to best serve this purpose.

Our mission: To enable rich, high-quality RTC applications to be developed for the browser, mobile platforms, and IoT devices, and allow them all to communicate via a common set of protocols.

The WebRTC initiative is a project supported by Google, Mozilla and Opera, amongst others.

Development

See here for instructions on how to get started developing with the native code.

Authoritative list of directories that contain the native API header files.

More info