mirror of
https://gitlab.freedesktop.org/xorg/xserver.git
synced 2026-05-03 00:48:04 +02:00
dri: prevent out-of-bounds read in dri3_fd_from_pixmap
Reported in #1817:
xwayland-24.1.6/redhat-linux-build/../dri3/dri3_screen.c:143:13:
warning[-Wanalyzer-out-of-bounds]: stack-based buffer over-read
xwayland-24.1.6/redhat-linux-build/../dri3/dri3_screen.c:143:13:
danger: out-of-bounds read from byte 16 till byte 19
but ‘fds’ ends at byte 16
141| int i;
142| for (i = 0; i < num_fds; i++)
143|-> close(fds[i]);
144| return -1;
145| }
Only possible if fds_from_pixmap returns a value > 4, but the analyzer
doesn't know the interface is defined not to do that.
Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com>
Part-of: <https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/2085>
(cherry picked from commit f05f269f1d)
This commit is contained in:
parent
375965221a
commit
4440c43c0c
1 changed files with 3 additions and 2 deletions
|
|
@ -138,9 +138,10 @@ dri3_fd_from_pixmap(PixmapPtr pixmap, CARD16 *stride, CARD32 *size)
|
|||
num_fds = info->fds_from_pixmap(screen, pixmap, fds, strides, offsets,
|
||||
&modifier);
|
||||
if (num_fds != 1 || offsets[0] != 0) {
|
||||
int i;
|
||||
for (i = 0; i < num_fds; i++)
|
||||
for (int i = 0; i < num_fds; i++) {
|
||||
BUG_RETURN_VAL(i >= ARRAY_SIZE(fds), -1);
|
||||
close(fds[i]);
|
||||
}
|
||||
return -1;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue