mirror of
https://github.com/X11Libre/xserver.git
synced 2026-10-01 22:03:09 +00:00
Bug #594: CAN-2005-2495: Fix exploitable integer overflow in pixmap
creation, where we could create a far smaller pixmap than we thought,
allowing changes to arbitrary chunks of memory. (Søren Sandmann
Pedersen)
This commit is contained in:
parent
b290884719
commit
c3d6799cee
16 changed files with 73 additions and 13 deletions
|
|
@ -376,6 +376,9 @@ exaCreatePixmap(ScreenPtr pScreen, int w, int h, int depth)
|
|||
ScrnInfoPtr pScrn = XF86SCRNINFO(pScreen);
|
||||
ExaScreenPriv(pScreen);
|
||||
|
||||
if (w > 32767 || h > 32767)
|
||||
return NullPixmap;
|
||||
|
||||
if (!pScrn->vtSema || pExaScr->swappedOut) {
|
||||
pPixmap = pExaScr->SavedCreatePixmap(pScreen, w, h, depth);
|
||||
} else {
|
||||
|
|
|
|||
|
|
@ -376,6 +376,9 @@ exaCreatePixmap(ScreenPtr pScreen, int w, int h, int depth)
|
|||
ScrnInfoPtr pScrn = XF86SCRNINFO(pScreen);
|
||||
ExaScreenPriv(pScreen);
|
||||
|
||||
if (w > 32767 || h > 32767)
|
||||
return NullPixmap;
|
||||
|
||||
if (!pScrn->vtSema || pExaScr->swappedOut) {
|
||||
pPixmap = pExaScr->SavedCreatePixmap(pScreen, w, h, depth);
|
||||
} else {
|
||||
|
|
|
|||
|
|
@ -376,6 +376,9 @@ exaCreatePixmap(ScreenPtr pScreen, int w, int h, int depth)
|
|||
ScrnInfoPtr pScrn = XF86SCRNINFO(pScreen);
|
||||
ExaScreenPriv(pScreen);
|
||||
|
||||
if (w > 32767 || h > 32767)
|
||||
return NullPixmap;
|
||||
|
||||
if (!pScrn->vtSema || pExaScr->swappedOut) {
|
||||
pPixmap = pExaScr->SavedCreatePixmap(pScreen, w, h, depth);
|
||||
} else {
|
||||
|
|
|
|||
Loading…
Reference in a new issue