High firefox Logic Error 🔧 Commit mapped

Overview

High
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
Impacthigh
DescriptionIncorrect boundary conditions in the Graphics: Text component
ComponentCore
Bug ClassLogic Error
Tracker2038537
Fix commite1b2f7ec555c (firefox) +84/-108
CISA KEVNot listed
Creditedtaiho kim
Disclosed2026-06-02

Files Changed

  • modules/freetype2/src/truetype/ttinterp.c
diff --git a/modules/freetype2/src/truetype/ttinterp.c b/modules/freetype2/src/truetype/ttinterp.c
index 3841118f14a..a975cce7eb3 100644
--- a/modules/freetype2/src/truetype/ttinterp.c
+++ b/modules/freetype2/src/truetype/ttinterp.c
@@ -1104,7 +1104,7 @@
   /* documentation is in freetype.h */
 
   static __inline FT_Int32
-  TT_MulFixi14_i386( FT_Int32  a,
+  TT_MulFix14_i386( FT_Int32  a,
                      FT_Int32  b )
   {
     FT_Int32  result;
@@ -2841,7 +2841,13 @@
         ARRAY_BOUND_ERROR;
     }
     else
+    {
+      Modify_CVT_Check( exc );
+      if ( exc->error )
+        return;
+
       exc->cvt[I] = FT_MulFix( args[1], exc->tt_metrics.scale );
+    }
   }
 
 
@@ -4923,37 +4929,38 @@
   Compute_Point_Displacement( TT_ExecContext  exc,
                               FT_F26Dot6*     x,
                               FT_F26Dot6*     y,
-                              TT_GlyphZone    zone,
-                              FT_UShort*      refp )
+                              FT_Vector*      cur,
+                              FT_UInt*        refp )
   {
-    TT_GlyphZoneRec  zp;
-    FT_UShort        p;
-    FT_F26Dot6       d;
+    TT_GlyphZone  zp;
+    FT_UShort     p;
+    FT_F26Dot6    d;
 
 
     if ( exc->opcode & 1 )
     {
-      zp = exc->zp0;
+      zp = &exc->zp0;
       p  = exc->GS.rp1;
     }
     else
     {
-      zp = exc->zp1;
+      zp = &exc->zp1;
       p  = exc->GS.rp2;
     }
 
-    if ( BOUNDS( p, zp.n_points ) )
+    if ( BOUNDS( p, zp->n_points ) )
     {
       if ( exc->pedantic_hinting )
         exc->error = FT_THROW( Invalid_Reference );
-      *refp = 0;
       return FAILURE;
     }
 
-    *zone = zp;
-    *refp = p;
+    /* return reference if zones match */
+    if ( refp )
+      *refp = cur == zp->cur ? p
+                             : ~0U;  /* nan */
 
-    d = PROJECT( zp.cur + p, zp.org + p );
+    d = PROJECT( zp->cur + p, zp->org + p );
 
     *x = FT_MulFix( d, exc->moveVector.x );
     *y = FT_MulFix( d, exc->moveVector.y );
@@ -4965,10 +4972,9 @@
   /* See `ttinterp.h' for details on backward compatibility mode. */
   static void
   Move_Zp2_Point( TT_ExecContext  exc,
-                  FT_UShort       point,
+                  FT_UInt         point,
                   FT_F26Dot6      dx,
-                  FT_F26Dot6      dy,
-                  FT_Bool         touch )
+                  FT_F26Dot6      dy )
   {
     if ( exc->GS.freeVector.x != 0 )
     {
@@ -4978,8 +4984,7 @@
 #endif
         exc->zp2.cur[point].x = ADD_LONG( exc->zp2.cur[point].x, dx );
 
-      if ( touch )
-        exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_X;
+      exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_X;
     }
 
     if ( exc->GS.freeVector.y != 0 )
@@ -4990,8 +4995,7 @@
 #endif
         exc->zp2.cur[point].y = ADD_LONG( exc->zp2.cur[point].y, dy );
 
-      if ( touch )
-        exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_Y;
+      exc->zp2.tags[point] |= FT_CURVE_TAG_TOUCH_Y;
     }
   }
 
@@ -5007,11 +5011,9 @@
            FT_Long*        args )
   {
     FT_Long          loop = exc->GS.loop;
-    TT_GlyphZoneRec  zp;
-    FT_UShort        refp;
 
     FT_F26Dot6       dx, dy;
-    FT_UShort        point;
+    FT_UInt          point;
 
 
     if ( exc->new_top < loop )
@@ -5023,12 +5025,12 @@
 
     exc->new_top -= loop;
 
-    if ( Compute_Point_Displacement( exc, &dx, &dy, &zp, &refp ) )
+    if ( Compute_Point_Displacement( exc, &dx, &dy, NULL, NULL ) )
       return;
 
     while ( loop-- )
     {
-      point = (FT_UShort)*(--args);
+      point = (FT_UInt)*(--args);
 
       if ( BOUNDS( point, exc->zp2.n_points ) )
       {
@@ -5039,7 +5041,7 @@
         }
       }
       else
-        Move_Zp2_Point( exc, point, dx, dy, TRUE );
+        Move_Zp2_Point( exc, point, dx, dy );
     }
 
   Fail:
@@ -5061,12 +5063,10 @@
   Ins_SHC( TT_ExecContext  exc,
            FT_Long*        args )
   {
-    TT_GlyphZoneRec  zp;
-    FT_UShort        refp;
+    FT_UInt          refp, start, limit, i;
     FT_F26Dot6       dx, dy;
 
     FT_UShort        contour, bounds;
-    FT_UShort        start, limit, i;
 
 
     contour = (FT_UShort)args[0];
@@ -5079,7 +5079,7 @@
       return;
     }
 
-    if ( Compute_Point_Displacement( exc, &dx, &dy, &zp, &refp ) )
+    if ( Compute_Point_Displacement( exc, &dx, &dy, exc->zp2.cur, &refp ) )
       return;
 
     if ( contour == 0 )
@@ -5095,8 +5095,8 @@
 
     for ( i = start; i < limit; i++ )
     {
-      if ( zp.cur != exc->zp2.cur || refp != i )
-        Move_Zp2_Point( exc, i, dx, dy, TRUE );
+      if ( refp != i )
+        Move_Zp2_Point( exc, i, dx, dy );
     }
   }
 
@@ -5111,38 +5111,59 @@
   Ins_SHZ( TT_ExecContext  exc,
            FT_Long*        args )
   {
-    TT_GlyphZoneRec  zp;
-    FT_UShort        refp;
-    FT_F26Dot6       dx,
-                     dy;
-
-    FT_UShort        limit, i;
+    FT_Vector*       cur;
+    FT_UInt          refp, i, limit;
+    FT_F26Dot6       dx, dy;
 
 
-    if ( BOUNDS( args[0], 2 ) )
+    /* XXX: UNDOCUMENTED! SHZ doesn't move the phantom points, */
+    /*      which must be subtracted.                          */
Loading diff…