Prevent 32-bit multiplication overflow

Basically impossible to achieve, but just in case
This commit is contained in:
Rangi
2026-07-07 17:02:46 -04:00
parent d94d0bcc2f
commit 5aedf31b46
2 changed files with 5 additions and 4 deletions
+3 -2
View File
@@ -100,7 +100,8 @@ Png::Png(char const *filename, std::streambuf &file) {
png, info, &width, &height, &bitDepth, &colorType, &interlaceType, nullptr, nullptr
);
pixels.resize(static_cast<size_t>(width) * static_cast<size_t>(height));
size_t nbPixels = static_cast<size_t>(width) * static_cast<size_t>(height);
pixels.resize(nbPixels);
auto colorTypeName = [](int type) {
switch (type) {
@@ -212,7 +213,7 @@ Png::Png(char const *filename, std::streambuf &file) {
assume(png_get_bit_depth(png, info) == 8);
// Now that metadata has been read, we can read the image data
std::vector<png_byte> image(width * height * 4);
std::vector<png_byte> image(nbPixels * 4);
std::vector<png_bytep> rowPtrs(height);
for (uint32_t y = 0; y < height; ++y) {
rowPtrs[y] = image.data() + y * width * 4;
+2 -2
View File
@@ -1146,10 +1146,10 @@ continue_visiting_tiles:;
uint32_t const nbTilesH = image.png.height / 8, nbTilesW = image.png.width / 8;
// Check the tile count
if (uint32_t nbTiles = nbTilesW * nbTilesH;
if (uint64_t nbTiles = nbTilesW * nbTilesH;
nbTiles > options.maxNbTiles[0] + options.maxNbTiles[1]) {
fatal(
"Image contains %" PRIu32 " tiles, exceeding the limit of %" PRIu16 " + %" PRIu16,
"Image contains %" PRIu64 " tiles, exceeding the limit of %" PRIu16 " + %" PRIu16,
nbTiles,
options.maxNbTiles[0],
options.maxNbTiles[1]