diff options
| author | Ferdinand Bachmann <ferdinand.bachmann@yrlf.at> | 2024-08-27 17:59:14 +0200 |
|---|---|---|
| committer | Ferdinand Bachmann <ferdinand.bachmann@yrlf.at> | 2024-08-27 18:16:43 +0200 |
| commit | 6245dcd57d3cb78aa1d9fdbf53832716478396ca (patch) | |
| tree | 421a6b8db598ed4c95aa27ef16ad96d8888d7fb1 /Source/Core/DiscIO | |
| parent | 27c71017fadd7c263acf193341075221f5cb9bb6 (diff) | |
RVZ: Fix undefined behaviour when copying 0 bytes to a null pointer
A vector of length 0 can have a null data pointer, which causes UB when
passed to memcpy, so only copy when we actually have data to copy. This
caused crashes in certain cases when compiling Dolphin with Clang and
LTO enabled.
Diffstat (limited to 'Source/Core/DiscIO')
| -rw-r--r-- | Source/Core/DiscIO/WIABlob.cpp | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/Source/Core/DiscIO/WIABlob.cpp b/Source/Core/DiscIO/WIABlob.cpp index 92bab36d81..10c4f261ed 100644 --- a/Source/Core/DiscIO/WIABlob.cpp +++ b/Source/Core/DiscIO/WIABlob.cpp @@ -765,7 +765,14 @@ bool WIARVZFileReader<RVZ>::Chunk::Decompress() const size_t bytes_to_move = m_out.bytes_written - m_out_bytes_used_for_exceptions; DecompressionBuffer in{std::vector<u8>(bytes_to_move), bytes_to_move}; - std::memcpy(in.data.data(), m_out.data.data() + m_out_bytes_used_for_exceptions, bytes_to_move); + + // Copying to a null pointer is undefined behaviour, so only copy when we + // actually have data to copy. + if (bytes_to_move > 0) + { + std::memcpy(in.data.data(), m_out.data.data() + m_out_bytes_used_for_exceptions, + bytes_to_move); + } m_out.bytes_written = m_out_bytes_used_for_exceptions; |
