https://bugs.kde.org/show_bug.cgi?id=525962

            Bug ID: 525962
           Summary: Crash: null m_lockedItem dereferenced when placing
                    several Typewriter annotations in a row
                    (pageviewannotator.cpp:1154)
    Classification: Applications
           Product: okular
      Version First unspecified
       Reported In:
          Platform: EndeavourOS
                OS: Linux
            Status: REPORTED
          Severity: crash
          Priority: NOR
         Component: PDF backend
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: ---

Created attachment 196377
  --> https://bugs.kde.org/attachment.cgi?id=196377&action=edit
Combined debug info: package versions, live gdb backtrace (full symbols) and
core dump state (m_lockedItem = 0x0, PickPointEngine alive)

SUMMARY
Okular crashes with SIGSEGV when placing several Typewriter annotations one
after another. In PageViewAnnotator::performRouteMouseOrTabletEvent(), the loop
that attaches the newly created annotations to the page dereferences
m_lockedItem without a null check:

    part/pageviewannotator.cpp:1154
    m_document->addPageAnnotation(m_lockedItem->pageNumber(), annotation);

>From the core dump:
  m_lockedItem        = (PageViewItem *) 0x0
  m_engine            = valid PickPointEngine
  m_engine->m_item    = 0x0
  m_creationCompleted = false

Both the annotator's locked item and the engine's own item pointer are null,
while the engine itself is still alive. The engine has already finished
creation and returned its annotations, so the crash happens at attach time,
not when the gesture starts.

STEPS TO REPRODUCE
1. Open any PDF document
2. Show the annotation toolbar (F6)
3. Select the "Typewriter" tool (Alt+5)
4. Click on the page, type some text, confirm the annotation
5. Immediately place another Typewriter annotation right next to the previous
one
6. Repeat step 5

OBSERVED RESULT
Okular crashes with SIGSEGV. The crash happens after 2 to 6 annotations -- the
exact count varies, but the crash itself is 100% reproducible: every single
attempt ends in a crash within a handful of annotations.

EXPECTED RESULT
Annotations are placed normally, no crash.

SOFTWARE/OS VERSIONS
Okular: 26.08.1
Operating System: Arch Linux (rolling, fully up to date, no partial upgrade)
Qt Version: 6.11.2-3
Graphics Platform: Wayland

ADDITIONAL INFORMATION
Crash occurs in the main thread while processing a mouse event; all other
threads are idle. Regardless of how m_lockedItem becomes null, the dereference
at line 1154 is unguarded and should be checked.

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to