mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-08-31 09:45:24 +02:00
RIFFReader::ReadData() trusted its count argument completely and memcpy'd straight from the internal buffer with no bounds check. Hardened it to clamp against the buffer and zero-fill any shortfall, as defense in depth. The actual reachable bug was in BackgroundAudio.cpp: it read a WAV 'smpl' chunk into a vector sized by GetCurrentChunkSize(), then unconditionally indexed smplData[28] (and, for the loop array, smplData[36]) with no check that the chunk was actually that large - a short/corrupt chunk in a game's background-music WAV caused a heap OOB read. Also fixes &smplData[0] being UB when the chunk is empty. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY