mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
Rely on PNG header dimension bounds
PNG replacement dimensions are validated by PNGHeaderPeek before the decoded buffer is allocated, so the additional size_t overflow checks are redundant.
This commit is contained in:
1 parent
9ad3b821d9
commit
90f7c6d195
1 file changed
+1
-10
@@ -16,7 +16,6 @@
|
||||
// https://github.com/hrydgard/ppsspp and http://www.ppsspp.org/.
|
||||
|
||||
#include <algorithm>
|
||||
#include <limits>
|
||||
|
||||
#include "ppsspp_config.h"
|
||||
|
||||
@@ -722,15 +721,7 @@ ReplacedTexture::LoadLevelResult ReplacedTexture::LoadLevelData(VFSFileReference
|
||||
png.format = PNG_FORMAT_RGBA;
|
||||
|
||||
std::vector<uint8_t> &out = data_[mipLevel];
|
||||
const size_t width = (size_t)level.w;
|
||||
const size_t height = (size_t)level.h;
|
||||
if (level.w <= 0 || level.h <= 0 ||
|
||||
width > std::numeric_limits<size_t>::max() / height ||
|
||||
width * height > std::numeric_limits<size_t>::max() / 4) {
|
||||
ERROR_LOG(Log::TexReplacement, "PNG replacement dimensions are too large: %s (%dx%d)", filename.c_str(), level.w, level.h);
|
||||
return LoadLevelResult::LOAD_ERROR;
|
||||
}
|
||||
out.resize(width * height * 4);
|
||||
out.resize(level.w * level.h * 4);
|
||||
if (!png_image_finish_read(&png, nullptr, &out[0], level.w * 4, nullptr)) {
|
||||
ERROR_LOG(Log::TexReplacement, "Could not load texture replacement: %s - %s", filename.c_str(), png.message);
|
||||
out.resize(0);
|
||||
|
||||
Reference in new issue
Block a user