diff options
Diffstat (limited to 'chromium/gpu/command_buffer/service/query_manager.cc')
-rw-r--r-- | chromium/gpu/command_buffer/service/query_manager.cc | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/chromium/gpu/command_buffer/service/query_manager.cc b/chromium/gpu/command_buffer/service/query_manager.cc index 85e273c6c3a..db508e0a7f7 100644 --- a/chromium/gpu/command_buffer/service/query_manager.cc +++ b/chromium/gpu/command_buffer/service/query_manager.cc @@ -98,6 +98,9 @@ bool AsyncPixelTransfersCompletedQuery::End(uint32 submit_count) { mem_params.shm_size = buffer.size; mem_params.shm_data_offset = shm_offset(); mem_params.shm_data_size = sizeof(QuerySync); + uint32 end = mem_params.shm_data_offset + mem_params.shm_data_size; + if (end > mem_params.shm_size || end < mem_params.shm_data_offset) + return false; observer_ = new AsyncPixelTransferCompletionObserverImpl(submit_count); |