From 373951897dd8e978ad2e8ccb63f33b6bb7ed37c4 Mon Sep 17 00:00:00 2001 From: yannaingtun Date: Tue, 11 Mar 2025 11:51:53 +0800 Subject: [PATCH] [atlas-aapt] fix buffer overflow vulnerability in deflatePrime function (CVE-2018-25032) --- atlas-aapt/external/zlib/src/deflate.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/atlas-aapt/external/zlib/src/deflate.c b/atlas-aapt/external/zlib/src/deflate.c index 696957705..868865cf4 100644 --- a/atlas-aapt/external/zlib/src/deflate.c +++ b/atlas-aapt/external/zlib/src/deflate.c @@ -471,7 +471,7 @@ int ZEXPORT deflatePrime (strm, bits, value) if (strm == Z_NULL || strm->state == Z_NULL) return Z_STREAM_ERROR; s = strm->state; - if ((Bytef *)(s->d_buf) < s->pending_out + ((Buf_size + 7) >> 3)) + if (s->sym_buf < s->pending_out + ((Buf_size + 7) >> 3)) return Z_BUF_ERROR; do { put = Buf_size - s->bi_valid;