From 6b5cba879c927d0f6d8cd8365056b103b6ba7324 Mon Sep 17 00:00:00 2001 From: VHANTOMI Date: Tue, 6 Oct 2026 23:23:05 +0200 Subject: [PATCH] Validate indexed BMP palette counts before reading ## Summary `gsKit_texture_bmp` allocates fixed-size color lookup tables for 4-bpp and 8-bpp images, but uses the BMP header's `ColorUsed` value without checking it before reading palette data. A malformed file can therefore make `fread` write past the allocated CLUT. Validate indexed-color palette counts before allocating or reading the palette. Reject counts larger than `2^BitCount`, and interpret a zero count as the format-defined maximum for 4-bpp and 8-bpp BMPs. ## Testing - Build gsKit with the PS2 toolchain. - Verify that valid 4-bpp and 8-bpp BMPs with `ColorUsed` set to zero or the maximum palette size still load. - Verify that malformed 4-bpp (`ColorUsed = 17`) and 8-bpp (`ColorUsed = 257`) BMPs are rejected before palette data is read. --- ee/toolkit/src/gsToolkit.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/ee/toolkit/src/gsToolkit.c b/ee/toolkit/src/gsToolkit.c index eadacda..c74c493 100644 --- a/ee/toolkit/src/gsToolkit.c +++ b/ee/toolkit/src/gsToolkit.c @@ -376,6 +376,20 @@ int gsKit_texture_bmp(GSGLOBAL *gsGlobal, GSTEXTURE *Texture, char *Path) return -1; } + if (Bitmap.InfoHeader.BitCount == 4 || Bitmap.InfoHeader.BitCount == 8) +{ + u32 MaxColors = 1u << Bitmap.InfoHeader.BitCount; + + if (Bitmap.InfoHeader.ColorUsed == 0) + Bitmap.InfoHeader.ColorUsed = MaxColors; + else if (Bitmap.InfoHeader.ColorUsed > MaxColors) + { + printf("BMP: Invalid color table size: %u\n", Bitmap.InfoHeader.ColorUsed); + fclose(File); + return -1; + } +} + Texture->Width = Bitmap.InfoHeader.Width; Texture->Height = Bitmap.InfoHeader.Height; Texture->Filter = GS_FILTER_NEAREST;