mirror of
https://github.com/encounter/rust-sdl2.git
synced 2026-07-10 21:18:41 -07:00
audio: fix device name use-after-free in AudioDevice::open
Fixes a use-after-free in `AudioDevice::open`, which occurs when selecting a particular device by name (as opposed to using a default device). Specifically, when extracting a C-style string pointer from a `Option<CString>`, the option was consumed, its contents turned into a pointer, and the original `CString` dropped. After that the C-style string pointer is dangling, as its backing rust CString has been freed. To fix this, the CString must be kept alive, which is achieved by simply creating an intermediary `Option<&CString>`, and consuming that.
This commit is contained in:
+4
-1
@@ -652,7 +652,10 @@ impl<CB: AudioCallback> AudioDevice<CB> {
|
||||
Some(device) => Some(CString::new(device).unwrap()),
|
||||
None => None
|
||||
};
|
||||
let device_ptr = device.map_or(ptr::null(), |s| s.as_ptr());
|
||||
// Warning: map_or consumes its argument; `device.map_or()` would therefore consume the
|
||||
// CString and drop it, making device_ptr a dangling pointer! To avoid that we downgrade
|
||||
// device to an Option<&_> first.
|
||||
let device_ptr = device.as_ref().map_or(ptr::null(), |s| s.as_ptr());
|
||||
|
||||
let iscapture_flag = if capture { 1 } else { 0 };
|
||||
let device_id = sys::SDL_OpenAudioDevice(
|
||||
|
||||
Reference in New Issue
Block a user