GPU: Reject savestates with display list ids out of range

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
Henrik RydgårdandClaude Opus 5.5 committed 2026-09-28 09:34:05 -06:00
1 parent 84f64a9fdf
commit 4bfaab058b
1 file changed
+11
+11
View File
@@ -1712,6 +1712,17 @@ void GPUCommon::DoState(PointerWrap &p) {
currentID = (int)(currentList - &dls[0]);
}
Do(p, currentID);
if (p.mode == PointerWrap::MODE_READ) {
bool valid = currentID >= 0 && currentID < DisplayListMaxCount;
for (int id : dlQueue) {
valid = valid && id >= 0 && id < DisplayListMaxCount;
}
if (!valid) {
ERROR_LOG(Log::G3D, "Savestate has an invalid display list id");
p.SetError(p.ERROR_FAILURE);
return;
}
}
// List 0 looks the same as no list here, but no list means an empty queue.
if (currentID == 0 && (dlQueue.empty() || dlQueue.front() != 0)) {
currentList = nullptr;