diff options
author | wolfbeast <mcwerewolf@gmail.com> | 2017-06-20 17:50:15 +0200 |
---|---|---|
committer | wolfbeast <mcwerewolf@gmail.com> | 2018-02-05 15:52:58 +0100 |
commit | 74fd80eecb5a4a8e91520c4ecd2c995ecc6c1418 (patch) | |
tree | f039dc21944278c3ea4895eab733ac55aab99a89 /gfx | |
parent | 9a3db97eb99e5880bf1d968c8ca1a05ff7c905bb (diff) | |
download | aura-central-74fd80eecb5a4a8e91520c4ecd2c995ecc6c1418.tar.gz |
Check for too large allocation size in BasicPlanarYCbCrImage::CopyData (DiD)
Diffstat (limited to 'gfx')
-rw-r--r-- | gfx/layers/basic/BasicImages.cpp | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/gfx/layers/basic/BasicImages.cpp b/gfx/layers/basic/BasicImages.cpp index ed9447207..fc1be6e9a 100644 --- a/gfx/layers/basic/BasicImages.cpp +++ b/gfx/layers/basic/BasicImages.cpp @@ -11,6 +11,7 @@ #include "gfxASurface.h" // for gfxASurface, etc #include "gfxPlatform.h" // for gfxPlatform, gfxImageFormat #include "gfxUtils.h" // for gfxUtils +#include "mozilla/CheckedInt.h" #include "mozilla/mozalloc.h" // for operator delete[], etc #include "mozilla/RefPtr.h" #include "mozilla/UniquePtr.h" @@ -111,7 +112,13 @@ BasicPlanarYCbCrImage::CopyData(const Data& aData) gfxImageFormat iFormat = gfx::SurfaceFormatToImageFormat(format); mStride = gfxASurface::FormatStrideForWidth(iFormat, size.width); - mDecodedBuffer = AllocateBuffer(size.height * mStride); + mozilla::CheckedInt32 requiredBytes = + mozilla::CheckedInt32(size.height) * mozilla::CheckedInt32(mStride); + if (!requiredBytes.isValid()) { + // invalid size + return false; + } + mDecodedBuffer = AllocateBuffer(requiredBytes.value()); if (!mDecodedBuffer) { // out of memory return false; |