summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorrago <rago@google.com>2016-08-22 17:59:38 -0700
committerJessica Wagantall <jwagantall@cyngn.com>2016-11-15 17:42:35 -0700
commitc7765a783a73525adf8df79bd5da4a23553a7468 (patch)
treea1680cf1bf4a6db47f983b9fefaa040191e4e742
parentf5a1842929b19917c6cdef2a2c701db8db8d9014 (diff)
downloadhardware_qcom_audio-cm-12.1-caf-8974.tar.gz
hardware_qcom_audio-cm-12.1-caf-8974.tar.bz2
hardware_qcom_audio-cm-12.1-caf-8974.zip
Fix potential overflow in Visualizer effectcm-12.1-caf-8974
CYNGNOS-3303 Bug: 30229821 Change-Id: Iea1c4a21735e893aeded95b980044ec0861a7ea8 (cherry picked from commit 2fa52194ef64843c2908c69527384c6c2fcdbafa) (cherry picked from commit 57ac66340ad488a17fc285b6fc2635cb7375d72b)
-rw-r--r--visualizer/offload_visualizer.c8
1 files changed, 8 insertions, 0 deletions
diff --git a/visualizer/offload_visualizer.c b/visualizer/offload_visualizer.c
index dfa4a2dc..aee1d454 100644
--- a/visualizer/offload_visualizer.c
+++ b/visualizer/offload_visualizer.c
@@ -872,6 +872,14 @@ int visualizer_command(effect_context_t * context, uint32_t cmdCode, uint32_t cm
break;
case VISUALIZER_CMD_MEASURE: {
+ if (pReplyData == NULL || replySize == NULL ||
+ *replySize < (sizeof(int32_t) * MEASUREMENT_COUNT)) {
+ ALOGV("%s VISUALIZER_CMD_MEASURE error *replySize %d <"
+ "(sizeof(int32_t) * MEASUREMENT_COUNT) %d",
+ __func__, *replySize, sizeof(int32_t) * MEASUREMENT_COUNT);
+ android_errorWriteLog(0x534e4554, "30229821");
+ return -EINVAL;
+ }
uint16_t peak_u16 = 0;
float sum_rms_squared = 0.0f;
uint8_t nb_valid_meas = 0;