Fix for stack buffer overflow in ixheaacd_esbr_chirp_fac_calc.
We found that error return was not being handled properly in ixheaacd_applysbr() function. This led to a wrong value being propagated which led to a stack buffer overflow. Also, a flag for checking if any previous frames encountered a fatal error has been added to ensure that further processing of frames doesn't happen after encountering a fatal error. Bug:130219994 Bug:131307285 Test: vendor Change-Id: If7b3887afcb375dda292082438f61d156027b60e
This commit is contained in:
parent
bbe47acd49
commit
e34ec6918e
4 changed files with 10 additions and 6 deletions
|
|
@ -806,12 +806,15 @@ IA_ERRORCODE ixheaacd_dec_api(pVOID p_ia_enhaacplus_dec_obj, WORD32 i_cmd,
|
|||
switch (i_idx) {
|
||||
case IA_CMD_TYPE_DO_EXECUTE: {
|
||||
WORD32 err_code = 0;
|
||||
if (!p_obj_exhaacplus_dec->p_state_aac->ui_init_done) {
|
||||
if (!p_obj_exhaacplus_dec->p_state_aac->ui_init_done ||
|
||||
p_obj_exhaacplus_dec->p_state_aac->fatal_err_present) {
|
||||
err_code = IA_FATAL_ERROR;
|
||||
} else {
|
||||
err_code = ixheaacd_dec_execute(p_obj_exhaacplus_dec);
|
||||
}
|
||||
if (err_code != IA_NO_ERROR) {
|
||||
if (err_code < 0)
|
||||
p_obj_exhaacplus_dec->p_state_aac->fatal_err_present = 1;
|
||||
p_obj_exhaacplus_dec->p_state_aac->i_bytes_consumed =
|
||||
p_obj_exhaacplus_dec->p_state_aac->ui_in_bytes;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -610,7 +610,7 @@ WORD32 ixheaacd_derive_noise_freq_bnd_tbl(
|
|||
kx = pstr_freq_band_data->freq_band_table[HIGH][0];
|
||||
|
||||
if (ptr_header_data->noise_bands == 0) {
|
||||
pstr_freq_band_data->num_nf_bands = 1;
|
||||
temp = 1;
|
||||
} else {
|
||||
temp = pstr_common_tables->log_dual_is_table[k2] -
|
||||
pstr_common_tables->log_dual_is_table[kx];
|
||||
|
|
@ -620,13 +620,12 @@ WORD32 ixheaacd_derive_noise_freq_bnd_tbl(
|
|||
if (temp == 0) {
|
||||
temp = 1;
|
||||
}
|
||||
pstr_freq_band_data->num_nf_bands = temp;
|
||||
}
|
||||
pstr_freq_band_data->num_if_bands = pstr_freq_band_data->num_nf_bands;
|
||||
|
||||
if (pstr_freq_band_data->num_nf_bands > MAX_NOISE_COEFFS) {
|
||||
if (temp > MAX_NOISE_COEFFS) {
|
||||
return -1;
|
||||
}
|
||||
pstr_freq_band_data->num_nf_bands = temp;
|
||||
pstr_freq_band_data->num_if_bands = pstr_freq_band_data->num_nf_bands;
|
||||
{
|
||||
WORD16 i_k, k;
|
||||
WORD16 num, den;
|
||||
|
|
|
|||
|
|
@ -500,6 +500,7 @@ IA_ERRORCODE ixheaacd_applysbr(
|
|||
if (err || (ptr_header_data[k]->sync_state == SBR_NOT_INITIALIZED)) {
|
||||
WORD32 lr1 = ps_enable ? 2 : num_channels;
|
||||
ixheaacd_prepare_upsamp(ptr_header_data, pstr_sbr_channel, lr1);
|
||||
if (err) return err;
|
||||
}
|
||||
|
||||
if (frame_status && (ptr_header_data[k]->sync_state == SBR_ACTIVE)) {
|
||||
|
|
|
|||
|
|
@ -234,6 +234,7 @@ typedef struct ia_aac_dec_state_struct {
|
|||
ia_sbr_header_data_struct str_sbr_config;
|
||||
jmp_buf xaac_jmp_buf;
|
||||
WORD32 decode_create_done;
|
||||
WORD32 fatal_err_present;
|
||||
} ia_aac_dec_state_struct;
|
||||
|
||||
typedef struct ia_exhaacplus_dec_api_struct {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue