IconCache: Check entry lengths before allocating when loading the cache

The key was resized before its length was checked, and the data length
wasn't checked at all, so a corrupt icon.cache could make a multi-GB
allocation and crash every launch. The cache is only saved at a clean
exit, so a bad file stayed.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
Henrik RydgårdandClaude Opus 5.5 committed 2026-09-30 11:12:53 -06:00
1 parent b03374241b
commit d22f8e90a9
1 file changed
+5 -4
+5 -4
View File
@@ -79,13 +79,14 @@ bool IconCache::LoadFromFile(FILE *file) {
break;
}
std::string key;
key.resize(entryHeader.keyLen, 0);
if (entryHeader.keyLen > 0x1000) {
// Let's say this is invalid, probably a corrupted file.
if (entryHeader.keyLen > 0x1000 || entryHeader.dataLen > MAX_SAVED_CACHE_SIZE) {
// Let's say this is invalid, probably a corrupted file. Check before allocating.
break;
}
std::string key;
key.resize(entryHeader.keyLen, 0);
if (fread(&key[0], 1, entryHeader.keyLen, file) != entryHeader.keyLen) {
break;
}