Avoid of bounds memory reads when scaling and mirroring images

The bounds check we had wasn't complete for mirroring cases.

Task-number: QTBUG-65387
Change-Id: I5333912621c1223f83b4f1b95f2b16d12b520bd2
Reviewed-by: Lars Knoll <lars.knoll@qt.io>
Reviewed-by: Eirik Aavitsland <eirik.aavitsland@qt.io>
bb10
Allan Sandfeld Jensen 2018-03-22 15:35:34 +01:00
parent fae42e1e73
commit 1d616e764d
2 changed files with 30 additions and 0 deletions

View File

@ -137,6 +137,16 @@ void qt_scale_image_16bit(uchar *destPixels, int dbpl,
// this bounds check here is required as floating point rounding above might in some cases lead to
// w/h values that are one pixel too large, falling outside of the valid image area.
const int ystart = srcy >> 16;
if (ystart >= srch && iy < 0) {
srcy += iy;
--h;
}
const int xstart = basex >> 16;
if (xstart >= (int)(sbpl/sizeof(SRC)) && ix < 0) {
basex += ix;
--w;
}
int yend = (srcy + iy * (h - 1)) >> 16;
if (yend < 0 || yend >= srch)
--h;
@ -248,6 +258,16 @@ template <typename T> void qt_scale_image_32bit(uchar *destPixels, int dbpl,
// this bounds check here is required as floating point rounding above might in some cases lead to
// w/h values that are one pixel too large, falling outside of the valid image area.
const int ystart = srcy >> 16;
if (ystart >= srch && iy < 0) {
srcy += iy;
--h;
}
const int xstart = basex >> 16;
if (xstart >= (int)(sbpl/sizeof(quint32)) && ix < 0) {
basex += ix;
--w;
}
int yend = (srcy + iy * (h - 1)) >> 16;
if (yend < 0 || yend >= srch)
--h;

View File

@ -558,6 +558,16 @@ void qt_scale_image_argb32_on_argb32_sse2(uchar *destPixels, int dbpl,
// this bounds check here is required as floating point rounding above might in some cases lead to
// w/h values that are one pixel too large, falling outside of the valid image area.
const int ystart = srcy >> 16;
if (ystart >= srch && iy < 0) {
srcy += iy;
--h;
}
const int xstart = basex >> 16;
if (xstart >= (int)(sbpl/sizeof(quint32)) && ix < 0) {
basex += ix;
--w;
}
int yend = (srcy + iy * (h - 1)) >> 16;
if (yend < 0 || yend >= srch)
--h;