Bug 256165
| Summary: | UBSan: RenderObjects sets height to number that doesn't fit in an integer | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | Seija K. <gfunni234> |
| Component: | WebCore Misc. | Assignee: | Nobody <webkit-unassigned> |
| Status: | NEW | ||
| Severity: | Normal | CC: | webkit-bug-importer |
| Priority: | P2 | Keywords: | InRadar |
| Version: | WebKit Nightly Build | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
Seija K.
If geometries has size 0 or whenever working on the first geometry, the height can be set to INT_MAX - INT_MIN, which cannot fit in a signed integer. We need to avoid this by specializing those cases.
| Attachments | ||
|---|---|---|
| Add attachment proposed patch, testcase, etc. |
Seija K.
Pull request: https://github.com/WebKit/WebKit/pull/13329
Radar WebKit Bug Importer
<rdar://problem/109041952>