From 506cfb6701ce8c3eaabdb677bd4d1cec3d0c814b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Henrik=20Rydg=C3=A5rd?= Date: Mon, 31 Aug 2026 15:37:32 +0200 Subject: [PATCH] Bound two values that texture packs and shader inis supply A hashrange of 'addr,w,h = 0,0' passed validation (0 isn't bigger than the source), became desc_.newW/newH, and ReplacedTexture::Prepare divides by them. A post-shader SSAA level multiplies the render resolution with no upper bound, while the texture-shader Scale sitting a few lines away is checked against 2..8. --- GPU/Common/PostShader.cpp | 6 ++++++ GPU/Common/TextureReplacer.cpp | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/GPU/Common/PostShader.cpp b/GPU/Common/PostShader.cpp index 2768cd211d..0603a25d08 100644 --- a/GPU/Common/PostShader.cpp +++ b/GPU/Common/PostShader.cpp @@ -163,6 +163,12 @@ void LoadPostShaderInfo(Draw::DrawContext *draw, const std::vector &direct section.Get("OutputResolution", &info.outputResolution); section.Get("Upscaling", &info.isUpscalingFilter); section.Get("SSAA", &info.SSAAFilterLevel); + if (info.SSAAFilterLevel < 0 || info.SSAAFilterLevel > 8) { + // It multiplies the render resolution, and shader inis come from downloads - + // the neighbouring texture-shader "Scale" is bounded for the same reason. + WARN_LOG(Log::G3D, "Ignoring out-of-range SSAA level %d in shader '%s'", info.SSAAFilterLevel, info.section.c_str()); + info.SSAAFilterLevel = 0; + } section.Get("60fps", &info.requires60fps); section.Get("UsePreviousFrame", &info.usePreviousFrame); diff --git a/GPU/Common/TextureReplacer.cpp b/GPU/Common/TextureReplacer.cpp index e7d035e26a..c6f98e4621 100644 --- a/GPU/Common/TextureReplacer.cpp +++ b/GPU/Common/TextureReplacer.cpp @@ -490,6 +490,12 @@ void TextureReplacer::ParseHashRange(const std::string &key, const std::string & return; } + if (toW == 0 || toH == 0) { + // These end up as desc_.newW/newH, which ReplacedTexture::Prepare divides by. + ERROR_LOG(Log::TexReplacement, "Ignoring invalid hashrange %s = %s, range is empty", key.c_str(), value.c_str()); + return; + } + const u64 rangeKey = ((u64)addr << 32) | ((u64)fromW << 16) | fromH; hashranges_[rangeKey] = WidthHeightPair(toW, toH); }