Fix MediaBuffer size-inflation off-by-32 bug

The MediaBuffer constructor taking an IMemory was advancing the data
pointer by sizeof(SharedControl) but was not reducing the size field,
leading to a 32-byte inflation in the reported size. This could cause
an out-of-bounds write if the buffer is the last carve-out in a page-exact
ashmem mapping.

This CL fixes the issue by correctly reducing the size field by
sizeof(SharedControl) when advancing the data pointer.

This was autogenerated by MendIt (go/androidmendit).

Bug: 503541238
Test: m libstagefright_foundation libstagefright
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:821190f16645f2a02f497b9e5eb8046a7ac2f9e8
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:4adcf41dddc3636fc96bb22656a617420ad950e6
Merged-In: Ie936d94d4b4d69b3fe582cdf315c12c7cb673011
Change-Id: Ie936d94d4b4d69b3fe582cdf315c12c7cb673011
1 file changed