From c226f3fc5cc40acfbb0a609f1dd91a2e964ac76f Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Wed, 15 Feb 2023 19:02:14 +0000 Subject: [PATCH] harfbuzz: add patch for CVE-2023-25193 using a limit of 256 as proposed in the discussion of https://github.com/harfbuzz/harfbuzz/commit/85be877925ddbf34f74a1229f3ca1716bb6170dc to reduce any effect on corner cases with unusual fonts --- .../harfbuzz/5.2.0-CVE-2023-25193.patch | 26 +++++++++++++++++++ .../libraries/harfbuzz/default.nix | 2 ++ 2 files changed, 28 insertions(+) create mode 100644 pkgs/development/libraries/harfbuzz/5.2.0-CVE-2023-25193.patch diff --git a/pkgs/development/libraries/harfbuzz/5.2.0-CVE-2023-25193.patch b/pkgs/development/libraries/harfbuzz/5.2.0-CVE-2023-25193.patch new file mode 100644 index 000000000000..93774cd8bace --- /dev/null +++ b/pkgs/development/libraries/harfbuzz/5.2.0-CVE-2023-25193.patch @@ -0,0 +1,26 @@ +Based on upstream 85be877925ddbf34f74a1229f3ca1716bb6170dc, with the +prior `stop` substitution included, though excluding the more recent +"unsafe-to-concat" clause as it is only a performance improvement +and I'm less certain of its portability. + +diff --git a/src/hb-ot-layout-gsubgpos.hh b/src/hb-ot-layout-gsubgpos.hh +index c15a42b0f..baa365e5e 100644 +--- a/src/hb-ot-layout-gsubgpos.hh ++++ b/src/hb-ot-layout-gsubgpos.hh +@@ -568,7 +568,15 @@ struct hb_ot_apply_context_t : + bool prev (unsigned *unsafe_from = nullptr) + { + assert (num_items > 0); +- while (idx > num_items - 1) ++ unsigned stop = num_items - 1; ++ ++ /* When looking back, limit how far we search; this function is mostly ++ * used for looking back for base glyphs when attaching marks. If we ++ * don't limit, we can get O(n^2) behavior where n is the number of ++ * consecutive marks. */ ++ stop = (unsigned) hb_max ((int) stop, (int) idx - 256); ++ ++ while (idx > stop) + { + idx--; + hb_glyph_info_t &info = c->buffer->out_info[idx]; diff --git a/pkgs/development/libraries/harfbuzz/default.nix b/pkgs/development/libraries/harfbuzz/default.nix index 5e892c1681c2..a986d052ef4e 100644 --- a/pkgs/development/libraries/harfbuzz/default.nix +++ b/pkgs/development/libraries/harfbuzz/default.nix @@ -45,6 +45,8 @@ stdenv.mkDerivation { sha256 = "0b4lpkidwx0lf8slczjji652yll6g5zgmm5lmisnb4s7gf8r8nkk"; }; + patches = [ ./5.2.0-CVE-2023-25193.patch ]; + postPatch = '' patchShebangs src/*.py test '' + lib.optionalString stdenv.isDarwin ''