Have any of the google-submitted vulnerability reports turned out to be invalid? Project Zero was pretty well regarded.
Yes I know about the asm code in ffmpeg though IDK if it's doing anything that could lead to a use after free error. I can understand if an OOB reference happens in the asm code since codecs are full of lookup tables and have to jump around inside video frames for motion estimation, but I'd hope no dynamic memory allocation is happening there. Instead it would be more like a GPU kernel. But, I haven't examined any of it.
Anyway there's a big difference between submitting concrete input data that causes an observable crash, and sending a pile of useless spew from a static analyzer and saying "here, have fun". The Curl guy was getting a lot of absolute crap submitted as reports.
From the GCC manual "bug criteria" section:
If the compiler gets a fatal signal, for any input whatever, that is a compiler bug. Reliable compilers never crash.
That sounds like timelessly good advice to me.