summaryrefslogtreecommitdiff
path: root/gfx
diff options
context:
space:
mode:
authorwolfbeast <mcwerewolf@gmail.com>2017-06-20 17:50:15 +0200
committerwolfbeast <mcwerewolf@gmail.com>2018-02-05 15:52:58 +0100
commit74fd80eecb5a4a8e91520c4ecd2c995ecc6c1418 (patch)
treef039dc21944278c3ea4895eab733ac55aab99a89 /gfx
parent9a3db97eb99e5880bf1d968c8ca1a05ff7c905bb (diff)
downloadaura-central-74fd80eecb5a4a8e91520c4ecd2c995ecc6c1418.tar.gz
Check for too large allocation size in BasicPlanarYCbCrImage::CopyData (DiD)
Diffstat (limited to 'gfx')
-rw-r--r--gfx/layers/basic/BasicImages.cpp9
1 files changed, 8 insertions, 1 deletions
diff --git a/gfx/layers/basic/BasicImages.cpp b/gfx/layers/basic/BasicImages.cpp
index ed9447207..fc1be6e9a 100644
--- a/gfx/layers/basic/BasicImages.cpp
+++ b/gfx/layers/basic/BasicImages.cpp
@@ -11,6 +11,7 @@
#include "gfxASurface.h" // for gfxASurface, etc
#include "gfxPlatform.h" // for gfxPlatform, gfxImageFormat
#include "gfxUtils.h" // for gfxUtils
+#include "mozilla/CheckedInt.h"
#include "mozilla/mozalloc.h" // for operator delete[], etc
#include "mozilla/RefPtr.h"
#include "mozilla/UniquePtr.h"
@@ -111,7 +112,13 @@ BasicPlanarYCbCrImage::CopyData(const Data& aData)
gfxImageFormat iFormat = gfx::SurfaceFormatToImageFormat(format);
mStride = gfxASurface::FormatStrideForWidth(iFormat, size.width);
- mDecodedBuffer = AllocateBuffer(size.height * mStride);
+ mozilla::CheckedInt32 requiredBytes =
+ mozilla::CheckedInt32(size.height) * mozilla::CheckedInt32(mStride);
+ if (!requiredBytes.isValid()) {
+ // invalid size
+ return false;
+ }
+ mDecodedBuffer = AllocateBuffer(requiredBytes.value());
if (!mDecodedBuffer) {
// out of memory
return false;