1From e6fda039ad638866b7a6a5d046f03278ba1b7611 Mon Sep 17 00:00:00 2001 2From: Werner Lemberg <wl@gnu.org> 3Date: Mon, 14 Nov 2022 19:18:19 +0100 4Subject: [PATCH] * src/truetype/ttgxvar.c (tt_hvadvance_adjust): Integer 5 overflow. 6 7Reported as 8 9 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50462 10--- 11 src/truetype/ttgxvar.c | 3 ++- 12 1 file changed, 2 insertions(+), 1 deletion(-) 13 14diff --git a/src/truetype/ttgxvar.c b/src/truetype/ttgxvar.c 15index aad3e29..a69a9b5 100644 16--- a/src/truetype/ttgxvar.c 17+++ b/src/truetype/ttgxvar.c 18@@ -42,6 +42,7 @@ 19 #include <ft2build.h> 20 #include <freetype/internal/ftdebug.h> 21 #include FT_CONFIG_CONFIG_H 22+#include <freetype/internal/ftcalc.h> 23 #include <freetype/internal/ftstream.h> 24 #include <freetype/internal/sfnt.h> 25 #include <freetype/tttags.h> 26@@ -1139,7 +1139,7 @@ 27 delta == 1 ? "" : "s", 28 vertical ? "VVAR" : "HVAR" )); 29 30- *avalue += delta; 31+ *avalue = ADD_INT(*avalue, delta ); 32 33 Exit: 34 return error; 35-- 362.33.0 37 38