Mercurial > vim
diff src/alloc.c @ 27453:c7f614c9ceb3 v8.2.4255
patch 8.2.4255: theoretical computation overflow
Commit: https://github.com/vim/vim/commit/d5cec1f1f055316c353cfa15ad8d5eb0952d50a0
Author: =?UTF-8?q?Dundar=20G=C3=B6c?= <gocdundar@gmail.com>
Date: Sat Jan 29 15:19:23 2022 +0000
patch 8.2.4255: theoretical computation overflow
Problem: Theoretical computation overflow.
Solution: Perform multiplication in a wider type. (closes https://github.com/vim/vim/issues/9657)
author | Bram Moolenaar <Bram@vim.org> |
---|---|
date | Sat, 29 Jan 2022 16:30:03 +0100 |
parents | 018c911eb9cf |
children | f34afadbef47 |
line wrap: on
line diff
--- a/src/alloc.c +++ b/src/alloc.c @@ -737,11 +737,11 @@ ga_grow_inner(garray_T *gap, int n) if (n < gap->ga_len / 2) n = gap->ga_len / 2; - new_len = gap->ga_itemsize * (gap->ga_len + n); + new_len = (size_t)gap->ga_itemsize * (gap->ga_len + n); pp = vim_realloc(gap->ga_data, new_len); if (pp == NULL) return FAIL; - old_len = gap->ga_itemsize * gap->ga_maxlen; + old_len = (size_t)gap->ga_itemsize * gap->ga_maxlen; vim_memset(pp + old_len, 0, new_len - old_len); gap->ga_maxlen = gap->ga_len + n; gap->ga_data = pp;