mirror of
https://github.com/asterisk/asterisk.git
synced 2026-07-22 14:34:09 -07:00
codec_codec2: Only process complete Codec2 frames in decoder
The codec2_samples() function uses floor division (160 * datalen/6) to compute expected output samples, but the decode loop condition (x < datalen) iterates with ceiling behavior when datalen is not a multiple of CODEC2_FRAME_LEN. This mismatch causes the loop to decode one extra frame beyond what the framework bounds check budgeted for, leading to an out-of-bounds write on the output buffer. Change the loop condition to only process complete frames, matching the floor-division behavior of codec2_samples(). This also prevents an out-of-bounds read on the input side when fewer than CODEC2_FRAME_LEN bytes remain. Resolves: #GHSA-qf8j-jp7h-c5hx
This commit is contained in:
committed by
George Joseph
parent
862a9248a0
commit
ab4b9c6b51
@@ -77,7 +77,7 @@ static int codec2tolin_framein(struct ast_trans_pvt *pvt, struct ast_frame *f)
|
||||
struct codec2_translator_pvt *tmp = pvt->pvt;
|
||||
int x;
|
||||
|
||||
for (x = 0; x < f->datalen; x += CODEC2_FRAME_LEN) {
|
||||
for (x = 0; x + CODEC2_FRAME_LEN <= f->datalen; x += CODEC2_FRAME_LEN) {
|
||||
unsigned char *src = f->data.ptr + x;
|
||||
int16_t *dst = pvt->outbuf.i16 + pvt->samples;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user