[media] Fix heap out-of-bounds write in MatroskaSource::read The root cause was incorrect pointer arithmetic where a byte-level offset (frame->range_offset()) was added directly to a uint16_t* pointer. This caused the effective byte offset to be doubled (scaled by the size of uint16_t), leading the subsequent ntohs() operation to write past the end of the allocated buffer. This change corrects the pointer arithmetic by casting the data pointer to uint8_t* before applying the range offset, ensuring the pointer advances by the correct number of bytes. Bug: 485020640 Test: Reproduced crash with PoC, verified patch fixes the issue. Flag: EXEMPT BUGFIX Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:11fab348d2f19f961aa5f77ebd982302b1c6fb97 Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:a4955af6dee107f449137db905e6817c10a76610 Merged-In: I723ea6520c30d3dcafb03bf15fabdd41ab58715f Change-Id: I723ea6520c30d3dcafb03bf15fabdd41ab58715f