From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id AC70BC433EF for ; Wed, 18 May 2022 05:36:35 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id C1CE084273; Wed, 18 May 2022 07:36:32 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="EQq2En3h"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 8C3DC8427B; Wed, 18 May 2022 07:36:31 +0200 (CEST) Received: from mail-pj1-x1033.google.com (mail-pj1-x1033.google.com [IPv6:2607:f8b0:4864:20::1033]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id D66D283C96 for ; Wed, 18 May 2022 07:36:28 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=bmeng.cn@gmail.com Received: by mail-pj1-x1033.google.com with SMTP id l20-20020a17090a409400b001dd2a9d555bso1025154pjg.0 for ; Tue, 17 May 2022 22:36:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=3pftUpuZPI9SdsGoyhGwOl1Nv3EPRL6bpFw5iOuLH9c=; b=EQq2En3hHd/Y91SmoE7tMTEuKZiwmrivgs5UGUNFf+cpCDXgEuc9m+YmGLLcncQOWb BqHcMIMGqLed6RZTr0/a4BnVfrJb8/V0E7nqUTvwSor7LT8voJZpMHDzrzDz0OY7rMnd nSGnDVSz+sCZ9Wnn4hjMbwZbuazCRg4c1jXUXx/95O7mpBK0rvAJDgUty3GatjsvKGlK THnF4HDM0Ag6/SHKsZp+NvklKBR/OLDkmXthHeJCGr/4koo6f8RXLXE+cj578xB/2ZOR GiWqssycUts11c5UL8z918gukdl5KnggDt03t4EPDo4AAXWz0e3wOc9DN9YhP7sOgoG1 lG2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=3pftUpuZPI9SdsGoyhGwOl1Nv3EPRL6bpFw5iOuLH9c=; b=LDBkgoY7mwhAFNk9Jhhd4lN4lp1Svx8+v3Ig/2MJySPJ2wTrFBgSGNrOMTXzTQkH6o 6lY4SJGkhrscYl9zw8VkwvaQC5+Jj6aJvq6/8khm0UZtWHmeu94s+WLX6CQaPvMJ58dW ZsQQG/Js/hwy+LT1nvgur6EH10LmTpYpVp1lOrprwi7Ed3zecjagsJYUi5tGutSPe2gE 4iUshZaYJ3kgbiAXYMSrxRWv3LgB05xIYOiXN2yQZ81Yuzei61x4jnsJKkCKkWqi6FQX jmL/mfloT2wFz6UW/DjlXi+KKAlITR2MQD2HShpCieVX2/ZvpSRQvgKHAELNeOC/9ekk 5+CQ== X-Gm-Message-State: AOAM5324pJx04mYOH4Pox43ks/B21jhtdgs6YKuai8UP00aWNTfeKh45 c/Bw1J6OWF2WY7pk58hM6J35e6gqvZM= X-Google-Smtp-Source: ABdhPJxC1gmbnAKp9ayGzuwFGxWKcE+PDaCBXxQvK7dPTUo7lcXrB//K+2BT8S+OA6nyrDecmPnSUw== X-Received: by 2002:a17:90b:3851:b0:1dc:4f70:1cb with SMTP id nl17-20020a17090b385100b001dc4f7001cbmr39710533pjb.167.1652852187284; Tue, 17 May 2022 22:36:27 -0700 (PDT) Received: from pek-vx-bsp2.wrs.com (unknown-176-192.windriver.com. [147.11.176.192]) by smtp.gmail.com with ESMTPSA id u10-20020a17090341ca00b001617aef3e08sm599690ple.51.2022.05.17.22.36.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 17 May 2022 22:36:26 -0700 (PDT) From: Bin Meng To: Anatolij Gustschin , u-boot@lists.denx.de Subject: [PATCH] driver: video: Check allocated pointers Date: Wed, 18 May 2022 13:36:18 +0800 Message-Id: <20220518053618.2638799-1-bmeng.cn@gmail.com> X-Mailer: git-send-email 2.25.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.5 at phobos.denx.de X-Virus-Status: Clean The codes that call STBTT_malloc() / stbtt__new_active() do not check the return value at present which may cause segfault. Signed-off-by: Bin Meng --- drivers/video/stb_truetype.h | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/drivers/video/stb_truetype.h b/drivers/video/stb_truetype.h index 26f4ac2ca8..438bfce468 100644 --- a/drivers/video/stb_truetype.h +++ b/drivers/video/stb_truetype.h @@ -1768,10 +1768,13 @@ static void stbtt__rasterize_sorted_edges(stbtt__bitmap *result, stbtt__edge *e, int s; // vertical subsample index unsigned char scanline_data[512], *scanline; - if (result->w > 512) + if (result->w > 512) { scanline = (unsigned char *) STBTT_malloc(result->w, userdata); - else + if (!scanline) + return; + } else { scanline = scanline_data; + } y = off_y * vsubsample; e[n].y0 = (off_y + result->h) * (float) vsubsample + 1; @@ -1821,6 +1824,8 @@ static void stbtt__rasterize_sorted_edges(stbtt__bitmap *result, stbtt__edge *e, while (e->y0 <= scan_y) { if (e->y1 > scan_y) { stbtt__active_edge *z = stbtt__new_active(&hh, e, off_x, scan_y, userdata); + if (!z) + return; // find insertion point if (active == NULL) active = z; @@ -2068,10 +2073,13 @@ static void stbtt__rasterize_sorted_edges(stbtt__bitmap *result, stbtt__edge *e, int y,j=0, i; float scanline_data[129], *scanline, *scanline2; - if (result->w > 64) + if (result->w > 64) { scanline = (float *) STBTT_malloc((result->w*2+1) * sizeof(float), userdata); - else + if (!scanline) + return; + } else { scanline = scanline_data; + } scanline2 = scanline + result->w; @@ -2105,6 +2113,8 @@ static void stbtt__rasterize_sorted_edges(stbtt__bitmap *result, stbtt__edge *e, while (e->y0 <= scan_y_bottom) { if (e->y0 != e->y1) { stbtt__active_edge *z = stbtt__new_active(&hh, e, off_x, scan_y_top, userdata); + if (!z) + return; STBTT_assert(z->ey >= scan_y_top); // insert at front z->next = active; -- 2.25.1