From 980f66ea59a57c7a1633916c3862d5399eedc703 Mon Sep 17 00:00:00 2001 From: Ray Essick Date: Fri, 24 Sep 2021 12:55:35 -0700 Subject: [PATCH] Guard against negative sizes from codec Protect against a negative codec buffer sizes. Avoids casting a negative size to a very large size. Bug: 193904641 Test: soundpool invocations during boot Change-Id: If0e71537ca6301344df1f2f1493ed6b81bbed1f3 --- media/jni/soundpool/Sound.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/media/jni/soundpool/Sound.cpp b/media/jni/soundpool/Sound.cpp index 6ef074090df87..ac5f35fd1e315 100644 --- a/media/jni/soundpool/Sound.cpp +++ b/media/jni/soundpool/Sound.cpp @@ -140,7 +140,7 @@ static status_t decode(int fd, int64_t offset, int64_t length, __func__); break; } - const size_t dataSize = std::min((size_t)info.size, available); + const size_t dataSize = std::min(available, (size_t)std::max(info.size, 0)); memcpy(writePos, buf + info.offset, dataSize); writePos += dataSize; written += dataSize;