Firefox · Graphics
CVE-2025-13012
Race in Graphics
Overview
High
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Changed Functions
| Function | Change | Notes |
|---|---|---|
ifgfx/thebes/gfxPlatform.cpp |
modified |
Files Changed
gfx/thebes/gfxPlatform.cpp
Patch
diff --git a/gfx/thebes/gfxPlatform.cpp b/gfx/thebes/gfxPlatform.cpp
index ea53a98cceb..7b0522442f2 100644
--- a/gfx/thebes/gfxPlatform.cpp
+++ b/gfx/thebes/gfxPlatform.cpp
@@ -198,7 +198,9 @@ class CrashStatsLogForwarder : public mozilla::gfx::LogForwarder {
private:
// Helper for the Log()
- void UpdateCrashReport();
+ void UpdateCrashReport(const MutexAutoLock& aProofOfLock);
+ bool UpdateStringsVectorInternal(const std::string& aString,
+ const MutexAutoLock& aProofOfLock);
private:
LoggingRecord mBuffer;
@@ -227,6 +229,12 @@ LoggingRecord CrashStatsLogForwarder::LoggingRecordCopy() {
}
bool CrashStatsLogForwarder::UpdateStringsVector(const std::string& aString) {
+ MutexAutoLock lock(mMutex);
+ return UpdateStringsVectorInternal(aString, lock);
+}
+
+bool CrashStatsLogForwarder::UpdateStringsVectorInternal(
+ const std::string& aString, const MutexAutoLock& aProofOfLock) {
// We want at least the first one and the last one. Otherwise, no point.
if (mMaxCapacity < 2) {
return false;
@@ -254,7 +262,8 @@ bool CrashStatsLogForwarder::UpdateStringsVector(const std::string& aString) {
return true;
}
-void CrashStatsLogForwarder::UpdateCrashReport() {
+void CrashStatsLogForwarder::UpdateCrashReport(
+ const MutexAutoLock& aProofOfLock) {
std::stringstream message;
std::string logAnnotation;
@@ -321,8 +330,8 @@ void CrashStatsLogForwarder::Log(const std::string& aString) {
PROFILER_MARKER_TEXT("gfx::CriticalError", GRAPHICS, {},
nsDependentCString(aString.c_str()));
- if (UpdateStringsVector(aString)) {
- UpdateCrashReport();
+ if (UpdateStringsVectorInternal(aString, lock)) {
+ UpdateCrashReport(lock);
}
// Add it to the parent strings
Loading diff…
References
On This Page