[vlc-commits] [Git][videolan/vlc][master] 3 commits: demux: libasf: allocate a full asf_object_t instead of a asf_object_root_t

Steve Lhomme (@robUx4) gitlab at videolan.org
Mon Sep 28 16:06:25 UTC 2026



Steve Lhomme pushed to branch master at VideoLAN / VLC


Commits:
5860e06a by Steve Lhomme at 2026-09-28T15:20:01+00:00
demux: libasf: allocate a full asf_object_t instead of a asf_object_root_t

ASF_ReadObject() may memset() a asf_object_t object which may be bigger
than the size of the asf_object_root_t we allocated.

We verify that the 2 structures have the same offsets
as we return the asf_object_root_t variant of the pointer which will be free'd
later.

Fixes #30173

- - - - -
427392df by Steve Lhomme at 2026-09-28T15:20:01+00:00
demux: libasf: avoid casting objects passed to ASF_ReadObject()

- - - - -
320c0317 by Steve Lhomme at 2026-09-28T15:20:01+00:00
demux: libasf: avoid unnecessary pointer casting

- - - - -


1 changed file:

- modules/demux/asf/libasf.c


Changes:

=====================================
modules/demux/asf/libasf.c
=====================================
@@ -216,7 +216,7 @@ static int  ASF_ReadObject_Header( stream_t *s, asf_object_t *p_obj )
     {
         p_subobj = malloc( sizeof( asf_object_t ) );
 
-        if( !p_subobj || ASF_ReadObject( s, p_subobj, (asf_object_t*)p_hdr ) )
+        if( !p_subobj || ASF_ReadObject( s, p_subobj, p_obj ) )
         {
             free( p_subobj );
             break;
@@ -539,7 +539,7 @@ static int ASF_ReadObject_header_extension( stream_t *s, asf_object_t *p_obj )
         asf_object_t *p_child = malloc( sizeof( asf_object_t ) );
 
         if( p_child == NULL
-         || ASF_ReadObject( s, p_child, (asf_object_t*)p_he ) )
+         || ASF_ReadObject( s, p_child, p_obj ) )
         {
             free( p_child );
             break;
@@ -1027,7 +1027,7 @@ static int ASF_ReadObject_extended_stream_properties( stream_t *s,
         else
         {
             /* This p_sp will be inserted by ReadRoot later */
-            p_esp->p_sp = (asf_object_stream_properties_t*)p_sp;
+            p_esp->p_sp = &p_sp->stream_properties;
             ASF_ParentObject( p_obj, p_sp );
         }
     }
@@ -1818,11 +1818,14 @@ static void ASF_ObjectDumpDebug( vlc_object_t *p_obj,
  *****************************************************************************/
 asf_object_root_t *ASF_ReadObjectRoot( stream_t *s, int b_seekable )
 {
-    asf_object_root_t *p_root = malloc( sizeof( asf_object_root_t ) );
+    static_assert(offsetof(asf_object_root_t, p_next) == offsetof(asf_object_common_t, p_next),
+                           "bogus asf_object_root_t offset");
+    asf_object_t *p_obj_root = malloc( sizeof( *p_obj_root ) );
+    asf_object_root_t *p_root = &p_obj_root->root;
     asf_object_t *p_obj;
     uint64_t i_boundary = 0;
 
-    if( !p_root )
+    if( !p_obj_root )
         return NULL;
 
     p_root->i_type = ASF_OBJECT_ROOT;
@@ -1846,7 +1849,7 @@ asf_object_root_t *ASF_ReadObjectRoot( stream_t *s, int b_seekable )
     {
         p_obj = malloc( sizeof( asf_object_t ) );
 
-        if( !p_obj || ASF_ReadObject( s, p_obj, (asf_object_t*)p_root ) )
+        if( !p_obj || ASF_ReadObject( s, p_obj, p_obj_root ) )
         {
             free( p_obj );
             break;
@@ -1855,19 +1858,19 @@ asf_object_root_t *ASF_ReadObjectRoot( stream_t *s, int b_seekable )
         {
             case( ASF_OBJECT_HEADER ):
                 if ( p_root->p_index || p_root->p_data || p_root->p_hdr ) break;
-                p_root->p_hdr = (asf_object_header_t*)p_obj;
+                p_root->p_hdr = &p_obj->header;
                 break;
             case( ASF_OBJECT_DATA ):
                 if ( p_root->p_index || p_root->p_data ) break;
-                p_root->p_data = (asf_object_data_t*)p_obj;
+                p_root->p_data = &p_obj->data;
             break;
             case( ASF_OBJECT_INDEX ):
                 if ( p_root->p_index ) break;
-                p_root->p_index = (asf_object_index_t*)p_obj;
+                p_root->p_index = &p_obj->index;
                 break;
             case( ASF_OBJECT_TIMECODE_INDEX ):
                 if ( p_root->p_timecode_index ) break;
-                p_root->p_timecode_index = (asf_object_timecode_index_t*)p_obj;
+                p_root->p_timecode_index = &p_obj->timecode_index;
                 break;
             default:
                 msg_Warn( s, "unknown top-level object found: " GUID_FMT,
@@ -1919,7 +1922,7 @@ asf_object_root_t *ASF_ReadObjectRoot( stream_t *s, int b_seekable )
             }
 
             ASF_ObjectDumpDebug( VLC_OBJECT(s),
-                                 (asf_object_common_t*)p_root, 0 );
+                                 &p_obj_root->common, 0 );
             return p_root;
         }
         msg_Warn( s, "cannot find file properties object" );



View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/fbc9f55971c338d0d06de1d2fc60646839ec698e...320c0317f198cb130e6f60bef37efcddea1d834d

-- 
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/fbc9f55971c338d0d06de1d2fc60646839ec698e...320c0317f198cb130e6f60bef37efcddea1d834d
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the vlc-commits mailing list