DO NOT MERGE AudioFlinger: Check framecount overflow when creating track Test: Native POC Bug: 34749571 Change-Id: I7529658e52ac7e64d162eb5338f10fb25eaa8fe7 (cherry picked from commit 1883f69de5f2c4e71df58d5b71d7c39f9779b50c) (cherry picked from commit eaa3969f757291f151efedde17ec529b8659024d)
diff --git a/services/audioflinger/Tracks.cpp b/services/audioflinger/Tracks.cpp index 0e24b52..b6b09b6 100644 --- a/services/audioflinger/Tracks.cpp +++ b/services/audioflinger/Tracks.cpp
@@ -113,9 +113,24 @@ mUid = clientUid; // ALOGD("Creating track with %d buffers @ %d bytes", bufferCount, bufferSize); + + size_t bufferSize = buffer == NULL ? roundup(frameCount) : frameCount; + // check overflow when computing bufferSize due to multiplication by mFrameSize. + if (bufferSize < frameCount // roundup rounds down for values above UINT_MAX / 2 + || mFrameSize == 0 // format needs to be correct + || bufferSize > SIZE_MAX / mFrameSize) { + android_errorWriteLog(0x534e4554, "34749571"); + return; + } + bufferSize *= mFrameSize; + size_t size = sizeof(audio_track_cblk_t); - size_t bufferSize = (buffer == NULL ? roundup(frameCount) : frameCount) * mFrameSize; if (buffer == NULL && alloc == ALLOC_CBLK) { + // check overflow when computing allocation size for streaming tracks. + if (size > SIZE_MAX - bufferSize) { + android_errorWriteLog(0x534e4554, "34749571"); + return; + } size += bufferSize; }