Closed Bug 2020091 Opened 5 months ago Closed 5 months ago

check ImageDataSerializer return values for error in a few places

Categories

(Core :: Graphics, defect)

defect

Tracking

()

RESOLVED FIXED
150 Branch
Tracking Status
firefox-esr115 --- wontfix
firefox-esr140 149+ fixed
firefox148 --- wontfix
firefox149 --- fixed
firefox150 --- fixed

People

(Reporter: tnikkel, Assigned: tnikkel)

References

Details

(Keywords: sec-audit, Whiteboard: [adv-main149-][adv-ESR140.9-])

Attachments

(3 files)

Not checking these caused a few sec bugs to be filed for other places. Just check all the ones I found.

Attached file (secure)
Keywords: sec-audit
See Also: → CVE-2026-4713
Group: gfx-core-security → core-security-release
Status: NEW → RESOLVED
Closed: 5 months ago
Resolution: --- → FIXED
Target Milestone: --- → 150 Branch
Attached file (secure)
Attachment #9552235 - Flags: approval-mozilla-beta?

firefox-beta Uplift Approval Request

  • User impact if declined: checks return value of functions that validate image buffers instead of accepting them
  • Code covered by automated testing: yes
  • Fix verified in Nightly: no
  • Needs manual QE test: no
  • Steps to reproduce for manual QE testing:
  • Risk associated with taking this patch: low
  • Explanation of risk level: checks return value of functions that validate image buffers instead of accepting them
  • String changes made/needed: none
  • Is Android affected?: yes
Attached file (secure)
Attachment #9552241 - Flags: approval-mozilla-esr140?

firefox-esr140 Uplift Approval Request

  • User impact if declined: checks return value of functions that validate image buffers instead of accepting them
  • Code covered by automated testing: yes
  • Fix verified in Nightly: no
  • Needs manual QE test: no
  • Steps to reproduce for manual QE testing:
  • Risk associated with taking this patch: low
  • Explanation of risk level: checks return value of functions that validate image buffers instead of accepting them
  • String changes made/needed: none
  • Is Android affected?: yes
Attachment #9552235 - Flags: approval-mozilla-beta? → approval-mozilla-beta+

Timothy, your patch does not apply cleanly to beta, could you check this please? Thanks

Flags: needinfo?(tnikkel)

Please uplift these patches in the order bug 2018113, bug 2021592, then bug 2020091 (this bug). Not sure how best to represent that. I created the uplift requests in that order with those patches applied to the latest beta/esr 140 tree, so they should apply when done in that order.

Flags: needinfo?(tnikkel) → needinfo?(pascalc)

OK, there is a parent/child dependency in such cases that you can set when you use the Lando uplift process, otherwise mentioning what you just put in the comment in the uplift request form is fine :)

Flags: needinfo?(pascalc)

I thought moz-phab would have set the parent/child relationship because I had the changesets in my tree when I uplifted them, but I did a seperate uplift for each bug.

Attachment #9552241 - Flags: approval-mozilla-esr140? → approval-mozilla-esr140+

Backed out for causing crashtest failures

Flags: needinfo?(tnikkel)
QA Whiteboard: [sec] [uplift] [qa-triage-done-c150/b149]
Flags: needinfo?(tnikkel)
Whiteboard: [adv-main149-][adv-ESR140.9-]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: