Repository navigation
Conversation
…eateImage Commit 1272515 ("OpenCL: Add checks for image size") added a CL_MEM_OBJECT_ALLOCATION_FAILURE check that multiplies the image size with angle::CheckedNumeric, but it seeds the checked computation with `sliceSize`, which is itself computed with an unchecked `size_t` multiplication. image_row_pitch is attacker-controlled and only lower-bounded; without checked arithmetic the product can wrap and slip a tiny size past the allocation check while the raw pitch is kept in the image descriptor. Compute the slice size with checked arithmetic and reject on overflow. Bug: angleproject:444481344
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes an integer overflow bypass in OpenCL image size validation (
ValidateCreateImage).Details
Commit 1272515 added a
CL_MEM_OBJECT_ALLOCATION_FAILUREcheck usingCheckedNumeric, but it seeds the checked computation withsliceSize = imageHeight * rowPitch— computed with unchecked multiplication ~200 lines earlier.image_row_pitchis attacker-controlled (only lower-bounded by validation). Withheight=16384androw_pitch=2^50+4, the product wraps to 65536, passing the allocation check while the raw pitch is stored in the descriptor. Downstream,clEnqueueMapImagereturns the raw pitch, causing OOB accesses.The fix computes the slice size with checked arithmetic and rejects on overflow.
Testing
PoC reproduces the exact arithmetic: bypass confirmed before, blocked after. Legitimate case (1920x1080) still passes.
AI tool use disclosure: AI was used in part for code audit and patch drafting.