Skip to content

fix integer overflow in pwg_scan_measurement - #176

Open
tanjiroK-coder wants to merge 1 commit into
OpenPrinting:masterfrom
tanjiroK-coder:pwg-measurement-overflow
Open

tanjiroK-coder wants to merge 1 commit into
OpenPrinting:masterfrom
tanjiroK-coder:pwg-measurement-overflow

Conversation

@tanjiroK-coder

Copy link
Copy Markdown
Contributor
  1. the digit loop in pwg_scan_measurement accumulates into an int, so a name with ten or more digits wraps: pwgMediaForPWG("custom_max_9999999999x9999999999mm") gives width and length of -727380068.
  2. value * numer overflows on its own for much shorter names since numer is up to 100000 for metres: custom_max_1000000x1000000in gives -1754967296.

Both accumulators are long long now and the return saturates at INT_MAX, so valid names decode exactly as before. The size name is remote input, it comes in on media-supported/media-ready and reaches here via cupsCheckDestSupported and cupsGetDestMediaByName, where a negative width then defeats the custom-size range check. Turned up running -fsanitize=undefined over the media name parsers, which fires at pwg-media.c:1065 and :1086; the two testpwg cases fail on master and pass with the change.

Assisted-by: Claude Code:claude-opus-5

The digit loop accumulates into an int and the final conversion multiplies by up to 100000, so an over-large media size name decodes to a negative width and length instead of a clamped value.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant