From 93db2153c0eb686bb6e5259ce5b246c3f774a1e2 Mon Sep 17 00:00:00 2001 From: YellowNest <59575587+YellowNest@users.noreply.github.com> Date: Mon, 5 Oct 2026 16:52:01 +0200 Subject: [PATCH] Prevent out-of-bounds user image writes in menu background (#2548) Clip user image alpha writes to menu bitmap bounds --- Src/StartMenu/StartMenuDLL/MenuPaint.cpp | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/Src/StartMenu/StartMenuDLL/MenuPaint.cpp b/Src/StartMenu/StartMenuDLL/MenuPaint.cpp index 32bccd3..9ea9d67 100644 --- a/Src/StartMenu/StartMenuDLL/MenuPaint.cpp +++ b/Src/StartMenu/StartMenuDLL/MenuPaint.cpp @@ -1185,13 +1185,23 @@ void CMenuContainer::CreateBackground( int width1, int width2, int height1, int if (opacity!=MenuSkin::OPACITY_SOLID && !bMask) { - // set to opaque + // set the visible part to opaque. BitBlt/AlphaBlend above clip to + // the destination bitmap automatically, but this direct pixel pass + // must do the same before forming a pointer into the DIB. SelectObject(hdc,bmp0); // deselect m_Bitmap so all the GDI operations get flushed - unsigned int *bits2=bits+pos.y*totalWidth+pos.x; - alpha<<=24; - for (int y=0;y