[webkit-changes] [WebKit/WebKit] 6dd569: Cherry-pick 252432.940 at safari-7614-branch (e34a3c3...
Chirag Shah
noreply at github.com
Wed Jan 25 11:24:58 PST 2023
Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 6dd5690bed2cc05518d594287d6520a1847c1e96
https://github.com/WebKit/WebKit/commit/6dd5690bed2cc05518d594287d6520a1847c1e96
Author: Chirag M Shah <chirag_m_shah at apple.com>
Date: 2023-01-25 (Wed, 25 Jan 2023)
Changed paths:
M Source/WebCore/Modules/websockets/WebSocketDeflater.cpp
Log Message:
-----------
Cherry-pick 252432.940 at safari-7614-branch (e34a3c3b5918). rdar://problem/104648708
Fix int overflow leading to OOB write
rdar://problem/80071711
Reviewed by Chris Dumez and Ryan Haddad.
* Source/WebCore/Modules/websockets/WebSocketDeflater.cpp:
(WebCore::WebSocketDeflater::addBytes):
(WebCore::WebSocketDeflater::finish):
(WebCore::WebSocketInflater::addBytes):
(WebCore::WebSocketInflater::finish):
* Source/WebCore/rendering/updating/RenderTreeBuilder.cpp:
(WebCore::RenderTreeBuilder::destroy):
(WebCore::RenderTreeBuilder::attach):
(WebCore::RenderTreeBuilder::attachToRenderElementInternal):
* Source/WebCore/rendering/updating/RenderTreeUpdater.cpp:
(WebCore::RenderTreeUpdater::createTextRenderer):
Canonical link: https://commits.webkit.org/252432.940@safari-7614-branch
Canonical link: https://commits.webkit.org/259375@main
More information about the webkit-changes
mailing list