From 0ac0295b957c2331cd04d247f38c01b8bed2c382 Mon Sep 17 00:00:00 2001 From: metsw24-max Date: Sun, 21 Jun 2026 00:10:08 +0530 Subject: [PATCH] bound clahe width and height to avoid signed overflow --- lib/operation.mjs | 8 ++++---- test/unit/clahe.js | 10 ++++++++-- 2 files changed, 12 insertions(+), 6 deletions(-) diff --git a/lib/operation.mjs b/lib/operation.mjs index 7f761619a..0dd34da00 100644 --- a/lib/operation.mjs +++ b/lib/operation.mjs @@ -654,15 +654,15 @@ function normalize (options) { */ function clahe (options) { if (is.plainObject(options)) { - if (is.integer(options.width) && options.width > 0) { + if (is.integer(options.width) && is.inRange(options.width, 1, 65536)) { this.options.claheWidth = options.width; } else { - throw is.invalidParameterError('width', 'integer greater than zero', options.width); + throw is.invalidParameterError('width', 'integer between 1 and 65536', options.width); } - if (is.integer(options.height) && options.height > 0) { + if (is.integer(options.height) && is.inRange(options.height, 1, 65536)) { this.options.claheHeight = options.height; } else { - throw is.invalidParameterError('height', 'integer greater than zero', options.height); + throw is.invalidParameterError('height', 'integer between 1 and 65536', options.height); } if (is.defined(options.maxSlope)) { if (is.integer(options.maxSlope) && is.inRange(options.maxSlope, 0, 100)) { diff --git a/test/unit/clahe.js b/test/unit/clahe.js index 8917b600b..f2a3bdf4a 100644 --- a/test/unit/clahe.js +++ b/test/unit/clahe.js @@ -89,13 +89,16 @@ suite('Clahe', () => { }); test('invalid width', (t) => { - t.plan(4); + t.plan(5); t.assert.throws(() => { sharp(fixtures.inputJpgClahe).clahe({ width: 100.5, height: 100 }); }); t.assert.throws(() => { sharp(fixtures.inputJpgClahe).clahe({ width: -5, height: 100 }); }); + t.assert.throws(() => { + sharp(fixtures.inputJpgClahe).clahe({ width: 2 ** 32, height: 100 }); + }); t.assert.throws(() => { sharp(fixtures.inputJpgClahe).clahe({ width: true, height: 100 }); }); @@ -105,13 +108,16 @@ suite('Clahe', () => { }); test('invalid height', (t) => { - t.plan(4); + t.plan(5); t.assert.throws(() => { sharp(fixtures.inputJpgClahe).clahe({ width: 100, height: 100.5 }); }); t.assert.throws(() => { sharp(fixtures.inputJpgClahe).clahe({ width: 100, height: -5 }); }); + t.assert.throws(() => { + sharp(fixtures.inputJpgClahe).clahe({ width: 100, height: 2 ** 32 }); + }); t.assert.throws(() => { sharp(fixtures.inputJpgClahe).clahe({ width: 100, height: true }); });