[go: nahoru, domu]

Fix out-of-bounds read in sandbox broker.

It is unsafe to call GetActualBufferSize if the param count declared
by the buffer makes the min_declared_size larger than the buffer size.

BUG=772621

Cq-Include-Trybots: master.tryserver.chromium.win:win10_chromium_x64_rel_ng
Change-Id: I9d3930230442a055ac27aeafdff52d8b553ec214
Reviewed-on: https://chromium-review.googlesource.com/701283
Reviewed-by: Justin Schuh <jschuh@chromium.org>
Commit-Queue: Justin Schuh <jschuh@chromium.org>
Cr-Commit-Position: refs/heads/master@{#507329}
1 file changed