<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>225918</bug_id>
          
          <creation_ts>2021-05-18 08:21:37 -0700</creation_ts>
          <short_desc>ReadOnlySharedRingBufferStorage::updateFrameBounds() should validate boundsBufferSize</short_desc>
          <delta_ts>2021-05-18 09:08:17 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Media</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Chris Dumez">cdumez</reporter>
          <assigned_to name="Chris Dumez">cdumez</assigned_to>
          <cc>eric.carlson</cc>
    
    <cc>ggaren</cc>
    
    <cc>jer.noble</cc>
    
    <cc>peng.liu6</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>youennf</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1761157</commentid>
    <comment_count>0</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2021-05-18 08:21:37 -0700</bug_when>
    <thetext>ReadOnlySharedRingBufferStorage::updateFrameBounds() should validate boundsBufferSize.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1761158</commentid>
    <comment_count>1</comment_count>
      <attachid>428941</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2021-05-18 08:22:53 -0700</bug_when>
    <thetext>Created attachment 428941
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1761159</commentid>
    <comment_count>2</comment_count>
      <attachid>428942</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2021-05-18 08:23:18 -0700</bug_when>
    <thetext>Created attachment 428942
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1761173</commentid>
    <comment_count>3</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2021-05-18 09:07:13 -0700</bug_when>
    <thetext>Committed r277655 (237861@main): &lt;https://commits.webkit.org/237861@main&gt;

All reviewed patches have been landed. Closing bug and clearing flags on attachment 428942.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1761174</commentid>
    <comment_count>4</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2021-05-18 09:08:17 -0700</bug_when>
    <thetext>&lt;rdar://problem/78157772&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>428941</attachid>
            <date>2021-05-18 08:22:53 -0700</date>
            <delta_ts>2021-05-18 08:23:16 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-225918-20210518082253.patch</filename>
            <type>text/plain</type>
            <size>1908</size>
            <attacher name="Chris Dumez">cdumez</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjc3NjUyCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IGM3OTA3N2M2ZWM2NzE1Yjk2
MzdkYjAxOWVkZGM4OTUzOTUzNzc3ZGQuLmIwNGI5OTRhMDU4ODIwNTQ1MWJiNTQ3ZTQxZWI5YTNl
Y2U2OThhZWEgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYgQEAKKzIwMjEtMDUtMTggIENocmlzIER1
bWV6ICA8Y2R1bWV6QGFwcGxlLmNvbT4KKworICAgICAgICBSZWFkT25seVNoYXJlZFJpbmdCdWZm
ZXJTdG9yYWdlOjp1cGRhdGVGcmFtZUJvdW5kcygpIHNob3VsZCB2YWxpZGF0ZSBib3VuZHNCdWZm
ZXJTaXplCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0y
MjU5MTgKKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBS
ZWFkT25seVNoYXJlZFJpbmdCdWZmZXJTdG9yYWdlOjp1cGRhdGVGcmFtZUJvdW5kcygpIHNob3Vs
ZCB2YWxpZGF0ZSBib3VuZHNCdWZmZXJTaXplIHNpbmNlIHRoZQorICAgICAgICBwcm9jZXNzIHdy
aXRpbmcgdGhlIGJ1ZmZlciBzaXplIG9uIHRoZSBvdGhlciBlbmQgbWF5IG5vdCBiZSB0cnVzdGVk
LgorCisgICAgICAgICogU2hhcmVkL0NvY29hL1NoYXJlZFJpbmdCdWZmZXJTdG9yYWdlLmNwcDoK
KyAgICAgICAgKFdlYktpdDo6UmVhZE9ubHlTaGFyZWRSaW5nQnVmZmVyU3RvcmFnZTo6dXBkYXRl
RnJhbWVCb3VuZHMpOgorCiAyMDIxLTA1LTE4ICBZb3Vlbm4gRmFibGV0ICA8eW91ZW5uQGFwcGxl
LmNvbT4KIAogICAgICAgICBSZXN1cnJlY3QgV0tXZWJWaWV3IG1lZGlhIGNvbnRyb2xzIEFQSSBy
ZW1vdmVkIGluIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMjE5MjkK
ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQvU2hhcmVkL0NvY29hL1NoYXJlZFJpbmdCdWZmZXJT
dG9yYWdlLmNwcCBiL1NvdXJjZS9XZWJLaXQvU2hhcmVkL0NvY29hL1NoYXJlZFJpbmdCdWZmZXJT
dG9yYWdlLmNwcAppbmRleCAxNjcxOTUyNDZkY2Q0ZjdkZGYzNjliMjczMjkzNDliYWU0ZTcwZmM0
Li43Y2Q5NTY5MzViMDFiZWZmMjkzYmFiMWUwYjhkNjk0YTZhNzc3MDUwIDEwMDY0NAotLS0gYS9T
b3VyY2UvV2ViS2l0L1NoYXJlZC9Db2NvYS9TaGFyZWRSaW5nQnVmZmVyU3RvcmFnZS5jcHAKKysr
IGIvU291cmNlL1dlYktpdC9TaGFyZWQvQ29jb2EvU2hhcmVkUmluZ0J1ZmZlclN0b3JhZ2UuY3Bw
CkBAIC03MCw4ICs3MCwxMiBAQCB2b2lkIFJlYWRPbmx5U2hhcmVkUmluZ0J1ZmZlclN0b3JhZ2U6
OnVwZGF0ZUZyYW1lQm91bmRzKCkKICAgICAgICAgbV9zdGFydEZyYW1lID0gbV9lbmRGcmFtZSA9
IDA7CiAgICAgICAgIHJldHVybjsKICAgICB9Ci0KLSAgICBhdXRvIHBhaXIgPSBzaGFyZWRCb3Vu
ZHMtPmJvdW5kc0J1ZmZlcltzaGFyZWRCb3VuZHMtPmJvdW5kc0J1ZmZlckluZGV4LmxvYWQoc3Rk
OjptZW1vcnlfb3JkZXJfYWNxdWlyZSldOworICAgIHVuc2lnbmVkIGJvdW5kc0J1ZmZlckluZGV4
ID0gc2hhcmVkQm91bmRzLT5ib3VuZHNCdWZmZXJJbmRleC5sb2FkKHN0ZDo6bWVtb3J5X29yZGVy
X2FjcXVpcmUpOworICAgIGlmIChib3VuZHNCdWZmZXJJbmRleCA+PSBib3VuZHNCdWZmZXJTaXpl
KSB7CisgICAgICAgIG1fc3RhcnRGcmFtZSA9IG1fZW5kRnJhbWUgPSAwOworICAgICAgICByZXR1
cm47CisgICAgfQorICAgIGF1dG8gcGFpciA9IHNoYXJlZEJvdW5kcy0+Ym91bmRzQnVmZmVyW2Jv
dW5kc0J1ZmZlckluZGV4XTsKICAgICBtX3N0YXJ0RnJhbWUgPSBwYWlyLmZpcnN0OwogICAgIG1f
ZW5kRnJhbWUgPSBwYWlyLnNlY29uZDsKIH0K
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>428942</attachid>
            <date>2021-05-18 08:23:18 -0700</date>
            <delta_ts>2021-05-18 09:07:14 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-225918-20210518082317.patch</filename>
            <type>text/plain</type>
            <size>1918</size>
            <attacher name="Chris Dumez">cdumez</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjc3NjUyCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IGM3OTA3N2M2ZWM2NzE1Yjk2
MzdkYjAxOWVkZGM4OTUzOTUzNzc3ZGQuLmIwNGI5OTRhMDU4ODIwNTQ1MWJiNTQ3ZTQxZWI5YTNl
Y2U2OThhZWEgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYgQEAKKzIwMjEtMDUtMTggIENocmlzIER1
bWV6ICA8Y2R1bWV6QGFwcGxlLmNvbT4KKworICAgICAgICBSZWFkT25seVNoYXJlZFJpbmdCdWZm
ZXJTdG9yYWdlOjp1cGRhdGVGcmFtZUJvdW5kcygpIHNob3VsZCB2YWxpZGF0ZSBib3VuZHNCdWZm
ZXJTaXplCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0y
MjU5MTgKKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBS
ZWFkT25seVNoYXJlZFJpbmdCdWZmZXJTdG9yYWdlOjp1cGRhdGVGcmFtZUJvdW5kcygpIHNob3Vs
ZCB2YWxpZGF0ZSBib3VuZHNCdWZmZXJTaXplIHNpbmNlIHRoZQorICAgICAgICBwcm9jZXNzIHdy
aXRpbmcgdGhlIGJ1ZmZlciBzaXplIG9uIHRoZSBvdGhlciBlbmQgbWF5IG5vdCBiZSB0cnVzdGVk
LgorCisgICAgICAgICogU2hhcmVkL0NvY29hL1NoYXJlZFJpbmdCdWZmZXJTdG9yYWdlLmNwcDoK
KyAgICAgICAgKFdlYktpdDo6UmVhZE9ubHlTaGFyZWRSaW5nQnVmZmVyU3RvcmFnZTo6dXBkYXRl
RnJhbWVCb3VuZHMpOgorCiAyMDIxLTA1LTE4ICBZb3Vlbm4gRmFibGV0ICA8eW91ZW5uQGFwcGxl
LmNvbT4KIAogICAgICAgICBSZXN1cnJlY3QgV0tXZWJWaWV3IG1lZGlhIGNvbnRyb2xzIEFQSSBy
ZW1vdmVkIGluIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMjE5MjkK
ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQvU2hhcmVkL0NvY29hL1NoYXJlZFJpbmdCdWZmZXJT
dG9yYWdlLmNwcCBiL1NvdXJjZS9XZWJLaXQvU2hhcmVkL0NvY29hL1NoYXJlZFJpbmdCdWZmZXJT
dG9yYWdlLmNwcAppbmRleCAxNjcxOTUyNDZkY2Q0ZjdkZGYzNjliMjczMjkzNDliYWU0ZTcwZmM0
Li5mMmUzZTc0MmQwOGI1MTAxYmYyZDdkY2ZmMmZhODgyY2ZjNDFjMmUwIDEwMDY0NAotLS0gYS9T
b3VyY2UvV2ViS2l0L1NoYXJlZC9Db2NvYS9TaGFyZWRSaW5nQnVmZmVyU3RvcmFnZS5jcHAKKysr
IGIvU291cmNlL1dlYktpdC9TaGFyZWQvQ29jb2EvU2hhcmVkUmluZ0J1ZmZlclN0b3JhZ2UuY3Bw
CkBAIC03MCw4ICs3MCwxMiBAQCB2b2lkIFJlYWRPbmx5U2hhcmVkUmluZ0J1ZmZlclN0b3JhZ2U6
OnVwZGF0ZUZyYW1lQm91bmRzKCkKICAgICAgICAgbV9zdGFydEZyYW1lID0gbV9lbmRGcmFtZSA9
IDA7CiAgICAgICAgIHJldHVybjsKICAgICB9Ci0KLSAgICBhdXRvIHBhaXIgPSBzaGFyZWRCb3Vu
ZHMtPmJvdW5kc0J1ZmZlcltzaGFyZWRCb3VuZHMtPmJvdW5kc0J1ZmZlckluZGV4LmxvYWQoc3Rk
OjptZW1vcnlfb3JkZXJfYWNxdWlyZSldOworICAgIHVuc2lnbmVkIGJvdW5kc0J1ZmZlckluZGV4
ID0gc2hhcmVkQm91bmRzLT5ib3VuZHNCdWZmZXJJbmRleC5sb2FkKHN0ZDo6bWVtb3J5X29yZGVy
X2FjcXVpcmUpOworICAgIGlmIChVTkxJS0VMWShib3VuZHNCdWZmZXJJbmRleCA+PSBib3VuZHNC
dWZmZXJTaXplKSkgeworICAgICAgICBtX3N0YXJ0RnJhbWUgPSBtX2VuZEZyYW1lID0gMDsKKyAg
ICAgICAgcmV0dXJuOworICAgIH0KKyAgICBhdXRvIHBhaXIgPSBzaGFyZWRCb3VuZHMtPmJvdW5k
c0J1ZmZlcltib3VuZHNCdWZmZXJJbmRleF07CiAgICAgbV9zdGFydEZyYW1lID0gcGFpci5maXJz
dDsKICAgICBtX2VuZEZyYW1lID0gcGFpci5zZWNvbmQ7CiB9Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>