summaryrefslogtreecommitdiffstats
path: root/media/libstagefright/MPEG4Extractor.cpp
diff options
context:
space:
mode:
authorJessica Wagantall <jwagantall@cyngn.com>2016-04-05 12:31:20 -0700
committerJessica Wagantall <jwagantall@cyngn.com>2016-04-05 12:31:20 -0700
commit1ea1107de83c91b54f633640854bcb363516a44b (patch)
tree7152e21a1d1b552caa514e7364cbfeffe042e60c /media/libstagefright/MPEG4Extractor.cpp
parentf42cede4106389bc99c86dea857afd04b4a79805 (diff)
parent86967280c797ec37605c5833d4255f74937bf3da (diff)
downloadframeworks_av-1ea1107de83c91b54f633640854bcb363516a44b.zip
frameworks_av-1ea1107de83c91b54f633640854bcb363516a44b.tar.gz
frameworks_av-1ea1107de83c91b54f633640854bcb363516a44b.tar.bz2
Merge tag 'android-6.0.1_r24' into HEAD
Ticket: CYNGNOS-2213 Android 6.0.1 release 24
Diffstat (limited to 'media/libstagefright/MPEG4Extractor.cpp')
-rwxr-xr-xmedia/libstagefright/MPEG4Extractor.cpp10
1 files changed, 9 insertions, 1 deletions
diff --git a/media/libstagefright/MPEG4Extractor.cpp b/media/libstagefright/MPEG4Extractor.cpp
index c056a25..f606366 100755
--- a/media/libstagefright/MPEG4Extractor.cpp
+++ b/media/libstagefright/MPEG4Extractor.cpp
@@ -4261,7 +4261,15 @@ status_t MPEG4Source::read(
continue;
}
- CHECK(dstOffset + 4 <= mBuffer->size());
+ if (dstOffset > SIZE_MAX - 4 ||
+ dstOffset + 4 > SIZE_MAX - nalLength ||
+ dstOffset + 4 + nalLength > mBuffer->size()) {
+ ALOGE("b/27208621 : %zu %zu", dstOffset, mBuffer->size());
+ android_errorWriteLog(0x534e4554, "27208621");
+ mBuffer->release();
+ mBuffer = NULL;
+ return ERROR_MALFORMED;
+ }
dstData[dstOffset++] = 0;
dstData[dstOffset++] = 0;