Fedora Account System
Red Hat Associate
Red Hat Customer
glamor_upload_boxes() allocates the tmp_bits buffer (used for 24-bit to 32-bit depth conversion) based on the destination pixmap height, but indexes it using source coordinates (y1 - dy_dst + dy_src). When the source is taller than the destination, the source-relative offset exceeds the destination height, causing writes past the buffer end. Size the buffer to account for the source coordinate mapping: byte_stride * (pixmap->drawable.height - dy_dst + dy_src). This ensures the buffer covers the full range of source rows that will be accessed during the upload. This vulnerability was discovered by: Anonymous working with TrendAI Zero Day Initiative ZDI-CAN-32361