From 52bf98bb202383f7709705254913cb67db4d1ed4 Mon Sep 17 00:00:00 2001 From: jmestwa-coder Date: Tue, 2 Jun 2026 12:16:09 +0530 Subject: [PATCH] fix 32-bit overflow in LZW byte-list size calculation --- src/cgif_raw.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/cgif_raw.c b/src/cgif_raw.c index 56f9533..832a9d9 100644 --- a/src/cgif_raw.c +++ b/src/cgif_raw.c @@ -349,8 +349,8 @@ static int LZW_GenerateStream(LZWResult* pResult, const uint32_t numPixel, const // pack the generated LZW data into blocks of 255 bytes uint8_t *byteList; // lzw-data packed in byte-list uint8_t *byteListBlock; // lzw-data packed in byte-list with 255-block structure - uint64_t MaxByteListLen = MAX_CODE_LEN * lzwPos / 8ull + 2ull + 1ull; // conservative upper bound - uint64_t MaxByteListBlockLen = MAX_CODE_LEN * lzwPos * (BLOCK_SIZE + 1ull) / 8ull / BLOCK_SIZE + 2ull + 1ull +1ull; // conservative upper bound + uint64_t MaxByteListLen = (uint64_t)MAX_CODE_LEN * lzwPos / 8ull + 2ull + 1ull; // conservative upper bound + uint64_t MaxByteListBlockLen = (uint64_t)MAX_CODE_LEN * lzwPos * (BLOCK_SIZE + 1ull) / 8ull / BLOCK_SIZE + 2ull + 1ull +1ull; // conservative upper bound byteList = malloc(MaxByteListLen); byteListBlock = malloc(MaxByteListBlockLen); if(byteList == NULL || byteListBlock == NULL) {