Rely on PNG header dimension bounds

PNG replacement dimensions are validated by PNGHeaderPeek before the

decoded buffer is allocated, so the additional size_t overflow checks are

redundant.
This commit is contained in:
Acts1631 committed 2026-09-07 14:52:06 -04:00
1 parent 9ad3b821d9
commit 90f7c6d195
1 file changed
+1 -10
+1 -10
View File
@@ -16,7 +16,6 @@
// https://github.com/hrydgard/ppsspp and http://www.ppsspp.org/.
#include <algorithm>
#include <limits>
#include "ppsspp_config.h"
@@ -722,15 +721,7 @@ ReplacedTexture::LoadLevelResult ReplacedTexture::LoadLevelData(VFSFileReference
png.format = PNG_FORMAT_RGBA;
std::vector<uint8_t> &out = data_[mipLevel];
const size_t width = (size_t)level.w;
const size_t height = (size_t)level.h;
if (level.w <= 0 || level.h <= 0 ||
width > std::numeric_limits<size_t>::max() / height ||
width * height > std::numeric_limits<size_t>::max() / 4) {
ERROR_LOG(Log::TexReplacement, "PNG replacement dimensions are too large: %s (%dx%d)", filename.c_str(), level.w, level.h);
return LoadLevelResult::LOAD_ERROR;
}
out.resize(width * height * 4);
out.resize(level.w * level.h * 4);
if (!png_image_finish_read(&png, nullptr, &out[0], level.w * 4, nullptr)) {
ERROR_LOG(Log::TexReplacement, "Could not load texture replacement: %s - %s", filename.c_str(), png.message);
out.resize(0);