harfbuzz: add patch for CVE-2023-25193

using a limit of 256 as proposed in the discussion of
85be877925
to reduce any effect on corner cases with unusual fonts
This commit is contained in:
Robert Scott
2023-02-15 19:02:14 +00:00
parent 514186fb18
commit c226f3fc5c
2 changed files with 28 additions and 0 deletions

View File

@@ -0,0 +1,26 @@
Based on upstream 85be877925ddbf34f74a1229f3ca1716bb6170dc, with the
prior `stop` substitution included, though excluding the more recent
"unsafe-to-concat" clause as it is only a performance improvement
and I'm less certain of its portability.
diff --git a/src/hb-ot-layout-gsubgpos.hh b/src/hb-ot-layout-gsubgpos.hh
index c15a42b0f..baa365e5e 100644
--- a/src/hb-ot-layout-gsubgpos.hh
+++ b/src/hb-ot-layout-gsubgpos.hh
@@ -568,7 +568,15 @@ struct hb_ot_apply_context_t :
bool prev (unsigned *unsafe_from = nullptr)
{
assert (num_items > 0);
- while (idx > num_items - 1)
+ unsigned stop = num_items - 1;
+
+ /* When looking back, limit how far we search; this function is mostly
+ * used for looking back for base glyphs when attaching marks. If we
+ * don't limit, we can get O(n^2) behavior where n is the number of
+ * consecutive marks. */
+ stop = (unsigned) hb_max ((int) stop, (int) idx - 256);
+
+ while (idx > stop)
{
idx--;
hb_glyph_info_t &info = c->buffer->out_info[idx];

View File

@@ -45,6 +45,8 @@ stdenv.mkDerivation {
sha256 = "0b4lpkidwx0lf8slczjji652yll6g5zgmm5lmisnb4s7gf8r8nkk";
};
patches = [ ./5.2.0-CVE-2023-25193.patch ];
postPatch = ''
patchShebangs src/*.py test
'' + lib.optionalString stdenv.isDarwin ''