diff --git a/.pick_status.json b/.pick_status.json index e928deb494e..041409fcb94 100644 --- a/.pick_status.json +++ b/.pick_status.json @@ -454,7 +454,7 @@ "description": "util/primconvert: Avoid OoB with improbable draws", "nominated": true, "nomination_type": 0, - "resolution": 0, + "resolution": 1, "main_sha": null, "because_sha": null, "notes": null diff --git a/src/gallium/auxiliary/indices/u_primconvert.c b/src/gallium/auxiliary/indices/u_primconvert.c index fe0cdcf3ccd..876e35631e1 100644 --- a/src/gallium/auxiliary/indices/u_primconvert.c +++ b/src/gallium/auxiliary/indices/u_primconvert.c @@ -221,8 +221,13 @@ primconvert_init_draw(struct primconvert_context *pc, } /* (step 5: allocate gpu memory sized for the FINAL index count) */ - u_upload_alloc(pc->pipe->stream_uploader, 0, new_info->index_size * new_draw->count, 4, + uint64_t new_size = (uint64_t)new_info->index_size * new_draw->count; + if (new_size > UINT_MAX) + return false; + u_upload_alloc(pc->pipe->stream_uploader, 0, new_size, 4, &ib_offset, &new_info->index.resource, &dst); + if (!dst) + return false; new_draw->start = ib_offset / new_info->index_size; new_draw->index_bias = info->index_size ? draw.index_bias : 0;