Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 60afc2fd authored by Yin-Chia Yeh's avatar Yin-Chia Yeh
Browse files

Camera: fix use after free in sensor timestamp

The metadata object might be overriden later and has it memory
re-allocated; hence snaping the sensor timestamp value before
we call into any method that might change the metadata.

Test: build
Bug: 150944913
Change-Id: I0f944fc9133d3ab279859f20236d956d7ca338f8
parent 0b23d9c7
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -246,6 +246,8 @@ void sendCaptureResult(
                frameNumber);
        return;
    }
    nsecs_t sensorTimestamp = timestamp.data.i64[0];

    for (auto& physicalMetadata : captureResult.mPhysicalMetadatas) {
        camera_metadata_entry timestamp =
                physicalMetadata.mPhysicalCameraMetadata.find(ANDROID_SENSOR_TIMESTAMP);
@@ -337,7 +339,7 @@ void sendCaptureResult(
                CameraMetadata(m.mPhysicalCameraMetadata));
    }
    states.tagMonitor.monitorMetadata(TagMonitor::RESULT,
            frameNumber, timestamp.data.i64[0], captureResult.mMetadata,
            frameNumber, sensorTimestamp, captureResult.mMetadata,
            monitoredPhysicalMetadata);

    insertResultLocked(states, &captureResult, frameNumber);