Skip to content

Commit 02fba93

Browse files
passyurclaude
andcommitted
lass: fix reverb use-after-free in ConstructorCommon
The parameter shadowed the `percentReverb` member, so the member was never assigned -- left dangling (default/room-size ctors) or uninitialised (the `Envelope*` ctors, whose own parameter also shadows the member). This caused a use-after-free + double-free on the first reverb call, crashing renders that apply reverb. Assign `this->percentReverb` instead. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent fcee6c9 commit 02fba93

1 file changed

Lines changed: 11 additions & 4 deletions

File tree

‎LASS/src/Reverb.cpp‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -203,15 +203,22 @@ Reverb::Reverb(Envelope *percentReverb, float *combGainList, float *lpGainList,
203203
* the other reverb parameters
204204
* samplingRate - the sampling rate of the input sounds
205205
**/
206-
void Reverb::ConstructorCommon(Envelope *percentReverb, float *combGainList,
206+
void Reverb::ConstructorCommon(Envelope *percentReverbInput, float *combGainList,
207207
float *lpGainList, float gainAllPass, float delay,
208208
m_rate_type samplingRate)
209209
{
210210
long combdelay[REVERB_NUM_COMB_FILTERS];
211211
int i;
212-
Envelope* temp = new Envelope(*percentReverb);
213-
delete percentReverb;
214-
percentReverb = temp;
212+
// Own a private copy of the mix envelope, then release the caller's.
213+
// NOTE: this parameter used to be named 'percentReverb', which shadowed the
214+
// member of the same name -- so "percentReverb = temp" updated the local
215+
// pointer and never this->percentReverb. That left the member dangling
216+
// (default/room ctors) or uninitialised (the Envelope* ctors, whose own
217+
// parameter likewise shadows the member), causing a use-after-free +
218+
// double-free on the first reverb call. Assigning this->percentReverb here
219+
// is the intended behaviour.
220+
this->percentReverb = new Envelope(*percentReverbInput);
221+
delete percentReverbInput;
215222
// figure out allpass filter parameters
216223
//gainReverb = percentReverb; //these two lines need fixing
217224
// actually, the above and below two lines probably won't be needed

0 commit comments

Comments
 (0)