From 63ffbe33a5545eea9a007987d86ef7844daf141d Mon Sep 17 00:00:00 2001 From: Andrzej Kaczmarek Date: Tue, 14 Jan 2014 17:16:18 +0100 Subject: [PATCH] android/a2dp: Fix IPC response length calculation struct audio_rsp_open_stream has only zero-length array member thus its size equals to 0. We need to explicitly specify size of array element type here. --- android/a2dp.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/android/a2dp.c b/android/a2dp.c index 9f3164ac1..145cd6738 100644 --- a/android/a2dp.c +++ b/android/a2dp.c @@ -1088,8 +1088,8 @@ static void bt_stream_open(const void *buf, uint16_t len) return; } - len = sizeof(*rsp) + setup->preset->len; - rsp = g_malloc0(sizeof(*rsp) + setup->preset->len); + len = sizeof(struct audio_preset) + setup->preset->len; + rsp = g_malloc0(len); rsp->preset->len = setup->preset->len; memcpy(rsp->preset->data, setup->preset->data, setup->preset->len); -- 2.47.3