From: Marek Kasik Date: Thu, 21 May 2026 15:51:51 +0000 (+0200) Subject: SplashOutputDev: Fix integer overflow in tilingPatternFill X-Git-Tag: archive/raspbian/26.01.0-5+rpi1^2~2 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=7c80817226b449cebf6cf5f12aa39f2b3010f39e;p=poppler.git SplashOutputDev: Fix integer overflow in tilingPatternFill Origin: https://gitlab.freedesktop.org/poppler/poppler/-/commit/8352264766652b98336e92359a70b3161a9ab97a Bug-Debian: https://bugs.debian.org/1138708 Bug: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715 Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-10118 Use checkedMultiply() to check integer multiplication of surface size and number of repetitions to avoid integer overflow and possible memory issues. Fixes: #1715 Gbp-Pq: Name SplashOutputDev-Fix-integer-overflow-in-tilingPatter.patch --- diff --git a/poppler/SplashOutputDev.cc b/poppler/SplashOutputDev.cc index 356c4dd..184d37e 100644 --- a/poppler/SplashOutputDev.cc +++ b/poppler/SplashOutputDev.cc @@ -4341,7 +4341,7 @@ bool SplashOutputDev::tilingPatternFill(GfxState *state, Gfx *gfxA, Catalog * /* matc[2] = ctm[2]; matc[3] = ctm[3]; - if (surface_width == 0 || surface_height == 0 || repeatX * repeatY <= 4) { + if (surface_width == 0 || surface_height == 0 || repeatX * repeatY <= 4 || checkedMultiply(surface_width, repeatX, &result_width) || checkedMultiply(surface_height, repeatY, &result_height)) { state->setCTM(savedCTM[0], savedCTM[1], savedCTM[2], savedCTM[3], savedCTM[4], savedCTM[5]); return false; } @@ -4363,8 +4363,6 @@ bool SplashOutputDev::tilingPatternFill(GfxState *state, Gfx *gfxA, Catalog * /* kx = matc[0]; ky = matc[3] - (matc[1] * matc[2]) / matc[0]; } - result_width = surface_width * repeatX; - result_height = surface_height * repeatY; kx = result_width / (fabs(kx) + 1); ky = result_height / (fabs(ky) + 1); state->concatCTM(kx, 0, 0, ky, 0, 0);