[media] Fix heap out-of-bounds write in MatroskaSource::read

The root cause was incorrect pointer arithmetic where a byte-level
offset (frame->range_offset()) was added directly to a uint16_t*
pointer. This caused the effective byte offset to be doubled (scaled by
the size of uint16_t), leading the subsequent ntohs() operation to write
past the end of the allocated buffer.

This change corrects the pointer arithmetic by casting the data pointer
to uint8_t* before applying the range offset, ensuring the pointer
advances by the correct number of bytes.

Bug: 485020640
Test: Reproduced crash with PoC, verified patch fixes the issue.
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:11fab348d2f19f961aa5f77ebd982302b1c6fb97
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:a4955af6dee107f449137db905e6817c10a76610
Merged-In: I723ea6520c30d3dcafb03bf15fabdd41ab58715f
Change-Id: I723ea6520c30d3dcafb03bf15fabdd41ab58715f
1 file changed