#cwe-789
1 writeup.
-
Two bugs in basis_universal's KTX2 parser with the same root shape — a size check written as integer arithmetic on attacker-controlled numbers that overflow. A 16 GiB allocation bomb and a wrap-past-the-bounds-check out-of-bounds read.