diff --git a/src/libvterm/src/screen.c b/src/libvterm/src/screen.c index 3e72e4bbe6..e5d740b2d6 100644 --- a/src/libvterm/src/screen.c +++ b/src/libvterm/src/screen.c @@ -280,6 +280,12 @@ static int erase_internal(VTermRect rect, int selective, void *user) for(col = rect.start_col; col < rect.end_col; col++) { ScreenCell *cell = getcell(screen, row, col); + if (cell == NULL) + { + DEBUG_LOG2("libvterm: erase_internal() position invalid: %d / %d", + row, col); + return 1; + } if(selective && cell->pen.protected_cell) continue; diff --git a/src/libvterm/src/state.c b/src/libvterm/src/state.c index a621822333..dd25726db1 100644 --- a/src/libvterm/src/state.c +++ b/src/libvterm/src/state.c @@ -16,6 +16,12 @@ static int on_resize(int rows, int cols, void *user); static void putglyph(VTermState *state, const uint32_t chars[], int width, VTermPos pos) { VTermGlyphInfo info; + + if (pos.row >= state->rows) + { + DEBUG_LOG2("libvterm: putglyph() pos.row %d out of range (rows = %d)\n", pos.row, state.rows); + return; + } info.chars = chars; info.width = width; info.protected_cell = state->protected_cell; @@ -283,6 +289,11 @@ static int on_text(const char bytes[], size_t len, void *user) VTermPos oldpos = state->pos; + if (state->pos.row >= state->rows) + { + DEBUG_LOG2("libvterm: on_text() pos.row %d out of range (rows = %d)\n", state->pos.row, state.rows); + return 0; + } // We'll have at most len codepoints, plus one from a previous incomplete // sequence. codepoints = vterm_allocator_malloc(state->vt, (len + 1) * sizeof(uint32_t)); diff --git a/src/version.c b/src/version.c index e1a41fb435..d69b5608fb 100644 --- a/src/version.c +++ b/src/version.c @@ -754,6 +754,8 @@ static char *(features[]) = static int included_patches[] = { /* Add new patch number below this line */ +/**/ + 989, /**/ 988, /**/