Firefox · Core
CVE-2026-10701
Logic Error in Core
Overview
High
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Files Changed
modules/freetype2/src/truetype/ttinterp.c
Patch
diff --git a/modules/freetype2/src/truetype/ttinterp.c b/modules/freetype2/src/truetype/ttinterp.c
index 3841118f14a..a975cce7eb3 100644
--- a/modules/freetype2/src/truetype/ttinterp.c
+++ b/modules/freetype2/src/truetype/ttinterp.c
@@ -1104,7 +1104,7 @@
/* documentation is in freetype.h */
static __inline FT_Int32
- TT_MulFixi14_i386( FT_Int32 a,
+ TT_MulFix14_i386( FT_Int32 a,
FT_Int32 b )
{
FT_Int32 result;
@@ -2841,7 +2841,13 @@
ARRAY_BOUND_ERROR;
}
else
+ {
+ Modify_CVT_Check( exc );
+ if ( exc->error )
+ return;
+
exc->cvt[I] = FT_MulFix( args[1], exc->tt_metrics.scale );
+ }
}
@@ -4923,37 +4929,38 @@
Compute_Point_Displacement( TT_ExecContext exc,
FT_F26Dot6* x,
FT_F26Dot6* y,
- TT_GlyphZone zone,
- FT_UShort* refp )
+ FT_Vector* cur,
+ FT_UInt* refp )
{
- TT_GlyphZoneRec zp;
- FT_UShort p;
- FT_F26Dot6 d;
+ TT_GlyphZone zp;
+ FT_UShort p;
+ FT_F26Dot6 d;
if ( exc->opcode & 1 )
{
- zp = exc->zp0;
+ zp = &exc->zp0;
p = exc->GS.rp1;
}
else
{
- zp = exc->zp1;
+ zp = &exc->zp1;
p = exc->GS.rp2;
}
- if ( BOUNDS( p, zp.n_points ) )
+ if ( BOUNDS( p, zp->n_points ) )
{
if ( exc->pedantic_hinting )
exc->error = FT_THROW( Invalid_Reference );
- *refp = 0;
return FAILURE;
}
- *zone = zp;
- *refp = p;
+ /* return reference if zones match */
+ if ( refp )
+ *refp = cur == zp->cur ? p
+ : ~0U; /* nan */
- d = PROJECT( zp.cur + p, zp.org + p );
+ d = PROJECT( zp->cur + p, zp->org + p );
*x = FT_MulFix( d, exc->moveVector.x );
*y = FT_MulFix( d, exc->moveVector.y );
@@ -4965,10 +4972,9 @@
/* See `ttinterp.h' for details on backward compatibility mode. */
static void
Move_Zp2_Point( TT_ExecContext exc,
- FT_UShort point,
+ FT_UInt point,
FT_F26Dot6 dx,
- FT_F26Dot6 dy,
- FT_Bool touch )
+ FT_F26Dot6 dy )
{
if ( exc->GS.freeVector.x != 0 )
{
@@ -4978,8 +4984,7 @@
#endif
exc->zp2.cur[point].x = ADD_LONG( exc->zp2.cur[point].x, dx );
- if ( touch )
- exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_X;
+ exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_X;
}
if ( exc->GS.freeVector.y != 0 )
@@ -4990,8 +4995,7 @@
#endif
exc->zp2.cur[point].y = ADD_LONG( exc->zp2.cur[point].y, dy );
- if ( touch )
- exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_Y;
+ exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_Y;
}
}
@@ -5007,11 +5011,9 @@
FT_Long* args )
{
FT_Long loop = exc->GS.loop;
- TT_GlyphZoneRec zp;
- FT_UShort refp;
FT_F26Dot6 dx, dy;
- FT_UShort point;
+ FT_UInt point;
if ( exc->new_top < loop )
@@ -5023,12 +5025,12 @@
exc->new_top -= loop;
- if ( Compute_Point_Displacement( exc, &dx, &dy, &zp, &refp ) )
+ if ( Compute_Point_Displacement( exc, &dx, &dy, NULL, NULL ) )
return;
while ( loop-- )
{
- point = (FT_UShort)*(--args);
+ point = (FT_UInt)*(--args);
if ( BOUNDS( point, exc->zp2.n_points ) )
{
@@ -5039,7 +5041,7 @@
}
}
else
- Move_Zp2_Point( exc, point, dx, dy, TRUE );
+ Move_Zp2_Point( exc, point, dx, dy );
}
Fail:
@@ -5061,12 +5063,10 @@
Ins_SHC( TT_ExecContext exc,
FT_Long* args )
{
- TT_GlyphZoneRec zp;
- FT_UShort refp;
+ FT_UInt refp, start, limit, i;
FT_F26Dot6 dx, dy;
FT_UShort contour, bounds;
- FT_UShort start, limit, i;
contour = (FT_UShort)args[0];
@@ -5079,7 +5079,7 @@
return;
}
- if ( Compute_Point_Displacement( exc, &dx, &dy, &zp, &refp ) )
+ if ( Compute_Point_Displacement( exc, &dx, &dy, exc->zp2.cur, &refp ) )
return;
if ( contour == 0 )
@@ -5095,8 +5095,8 @@
for ( i = start; i < limit; i++ )
{
- if ( zp.cur != exc->zp2.cur || refp != i )
- Move_Zp2_Point( exc, i, dx, dy, TRUE );
+ if ( refp != i )
+ Move_Zp2_Point( exc, i, dx, dy );
}
}
@@ -5111,38 +5111,59 @@
Ins_SHZ( TT_ExecContext exc,
FT_Long* args )
{
- TT_GlyphZoneRec zp;
- FT_UShort refp;
- FT_F26Dot6 dx,
- dy;
-
- FT_UShort limit, i;
+ FT_Vector* cur;
+ FT_UInt refp, i, limit;
+ FT_F26Dot6 dx, dy;
- if ( BOUNDS( args[0], 2 ) )
+ /* XXX: UNDOCUMENTED! SHZ doesn't move the phantom points, */
+ /* which must be subtracted. */
Loading diff…
References
On This Page