Fix rare integer overflow in text shaping

With extreme painter scaling, linearAdvance may be too large to fit in
an unsigned short.

Fixes: QTBUG-91758
Pick-to: 6.1 5.15
Change-Id: I7bbe6e77ec9bcef4aa5259da1d3000ed1a8eb27a
Reviewed-by: Eskil Abrahamsen Blomfeldt <eskil.abrahamsen-blomfeldt@qt.io>
bb10
Paul Olav Tvete 2021-05-05 11:32:51 +02:00
parent 31defb8339
commit e2bdff3555
1 changed files with 2 additions and 1 deletions

View File

@ -1051,7 +1051,8 @@ QFontEngineFT::Glyph *QFontEngineFT::loadGlyph(QGlyphSet *set, uint glyph,
info.height = TRUNC(top - bottom);
// If any of the metrics are too large to fit, don't cache them
if (areMetricsTooLarge(info))
// Also, avoid integer overflow when linearAdvance is to large to fit in a signed short
if (areMetricsTooLarge(info) || info.linearAdvance > 0x7FFF)
return nullptr;
g = new Glyph;