Fix overflow-prone size check.

This commit is contained in:
Michael Grant
2026-10-09 22:55:15 +02:00
parent 5d1c25c5c9
commit 6826d87bdb
2 changed files with 2 additions and 2 deletions

View File

@@ -431,7 +431,7 @@ kitty_upload(struct tty *tty, struct image *im)
return (NULL);
upload_width = canvas_width + 2;
upload_height = canvas_height + 2;
if ((uint64_t)upload_width * upload_height * 4 > IMAGE_SIZE_LIMIT)
if ((uint64_t)upload_width * upload_height > IMAGE_SIZE_LIMIT / 4)
return (NULL);
for (entry = ko->images; entry != NULL; entry = entry->next) {

View File

@@ -966,7 +966,7 @@ image_create(u_int width, u_int height, u_int canvas_width,
if (width == 0 || height == 0 || canvas_width < width ||
canvas_height < height || sx == 0 || sy == 0 || pixels == NULL)
return (NULL);
if ((uint64_t)width * height * 4 > SIZE_MAX)
if ((uint64_t)width * height > SIZE_MAX / 4)
return (NULL);
if ((uint64_t)sx * sy > SIZE_MAX / sizeof *im->cells ||
sx > USHRT_MAX || sy > USHRT_MAX)