From ce6d92df9514fb15d427cf983df4e136e2caf3e5 Mon Sep 17 00:00:00 2001 From: Tristan Date: Thu, 26 Mar 2026 14:07:23 -0400 Subject: [PATCH] webp: validate dimensions in uncompressed alpha path The compressed alpha path (compression == 1) validates widthMinusOne and heightMinusOne against 0x3fff before use, but the uncompressed path (compression == 0) performs no validation. This inconsistency allows large dimension values through the uncompressed path, which can produce incorrect buffer sizes on 32-bit architectures where the w*h multiplication wraps around. Apply the same dimension check to both code paths for consistency. --- webp/decode.go | 3 +++ 1 file changed, 3 insertions(+) diff --git a/webp/decode.go b/webp/decode.go index 2371808f..e2b8de1a 100644 --- a/webp/decode.go +++ b/webp/decode.go @@ -157,6 +157,9 @@ func readAlpha(chunkData io.Reader, widthMinusOne, heightMinusOne uint32, compre switch compression { case 0: + if widthMinusOne > 0x3fff || heightMinusOne > 0x3fff { + return nil, 0, errors.New("webp: invalid format") + } w := int(widthMinusOne) + 1 h := int(heightMinusOne) + 1 alpha = make([]byte, w*h)