Skip to content

OpenCL: check image slice size computation for overflow in ValidateCreateImage - #109

Open
kalt2212 wants to merge 1 commit into
google:mainfrom
kalt2212:fix-cl-image-slice-overflow
Open

kalt2212 wants to merge 1 commit into
google:mainfrom
kalt2212:fix-cl-image-slice-overflow

Conversation

@kalt2212

@kalt2212 kalt2212 commented Oct 8, 2026

Copy link
Copy Markdown

Summary

Fixes an integer overflow bypass in OpenCL image size validation (ValidateCreateImage).

Details

Commit 1272515 added a CL_MEM_OBJECT_ALLOCATION_FAILURE check using CheckedNumeric, but it seeds the checked computation with sliceSize = imageHeight * rowPitch — computed with unchecked multiplication ~200 lines earlier.

image_row_pitch is attacker-controlled (only lower-bounded by validation). With height=16384 and row_pitch=2^50+4, the product wraps to 65536, passing the allocation check while the raw pitch is stored in the descriptor. Downstream, clEnqueueMapImage returns the raw pitch, causing OOB accesses.

The fix computes the slice size with checked arithmetic and rejects on overflow.

Testing

PoC reproduces the exact arithmetic: bypass confirmed before, blocked after. Legitimate case (1920x1080) still passes.


AI tool use disclosure: AI was used in part for code audit and patch drafting.

…eateImage

Commit 1272515 ("OpenCL: Add checks for image size") added a
CL_MEM_OBJECT_ALLOCATION_FAILURE check that multiplies the image size with
angle::CheckedNumeric, but it seeds the checked computation with `sliceSize`,
which is itself computed with an unchecked `size_t` multiplication.

image_row_pitch is attacker-controlled and only lower-bounded; without
checked arithmetic the product can wrap and slip a tiny size past the
allocation check while the raw pitch is kept in the image descriptor.

Compute the slice size with checked arithmetic and reject on overflow.

Bug: angleproject:444481344
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant