Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(475)

Unified Diff: src/images/SkImageRef.cpp

Issue 116773002: Fixed more fuzzer issues (Closed) Base URL: https://skia.googlesource.com/skia.git@master
Patch Set: Changed isAvailable for validateAvailable Created 7 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: src/images/SkImageRef.cpp
diff --git a/src/images/SkImageRef.cpp b/src/images/SkImageRef.cpp
index 716519f080d0ab8e2f9d2dc964b73eb80224406b..843f4c01f941d3aa9b962d785ba095122397bae0 100644
--- a/src/images/SkImageRef.cpp
+++ b/src/images/SkImageRef.cpp
@@ -165,8 +165,12 @@ SkImageRef::SkImageRef(SkFlattenableReadBuffer& buffer, SkBaseMutex* mutex)
fDoDither = buffer.readBool();
size_t length = buffer.getArrayCount();
- fStream = SkNEW_ARGS(SkMemoryStream, (length));
- buffer.readByteArray((void*)fStream->getMemoryBase(), length);
+ if (buffer.validateAvailable(length)) {
+ fStream = SkNEW_ARGS(SkMemoryStream, (length));
+ buffer.readByteArray((void*)fStream->getMemoryBase(), length);
+ } else {
+ fStream = NULL;
+ }
fPrev = fNext = NULL;
fFactory = NULL;
« src/effects/SkDisplacementMapEffect.cpp ('K') | « src/effects/gradients/SkGradientShader.cpp ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698