Index: src/typedarray.js |
diff --git a/src/typedarray.js b/src/typedarray.js |
index 21dd9c82d14f02d1d265f87604386e57cd09f890..c0f07eda85623defe627fa5f7d834bfb5f2ba6e5 100644 |
--- a/src/typedarray.js |
+++ b/src/typedarray.js |
@@ -243,6 +243,10 @@ function TypedArraySet(obj, offset) { |
if (intOffset < 0) { |
throw MakeTypeError("typed_array_set_negative_offset"); |
} |
+ |
+ if (intOffset > %MaxSmi()) { |
+ throw MakeRangeError("typed_array_set_source_too_large"); |
+ } |
switch (%TypedArraySetFastCases(this, obj, intOffset)) { |
// These numbers should be synchronized with runtime.cc. |
case 0: // TYPED_ARRAY_SET_TYPED_ARRAY_SAME_TYPE |