APNG frame buffer size: checked multiplication before allocation
Fixed in: Public fix committed 2026-04-23; first containing release not established
details
- Finding IDs
- F-FLUTTER-APNG-002
- Status
- fixed publicly
- Fixed in
- Public fix committed 2026-04-23; first containing release not established
- Recorded credit
- Public fix author: Jason Simmons. Public 1seal credit and a causal link to our report are not established.
- Note
- The public patch checks overflow in row-byte and pixel-buffer multiplication before allocation. It matches the frame-size calculation in the earlier report, separate from F-FLUTTER-APNG-001 (short fdAT chunks). No remote code execution claim or new product execution is made here.
F-FLUTTER-APNG-002: Memory safety. Unchecked multiplication can produce an incorrect APNG frame buffer size. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-FLUTTER-APNG-002
Security area (1seal assessment): Memory safety. Unchecked multiplication can produce an incorrect APNG frame buffer size. Reviewed 7 Oct 2026.