https://bugs.kde.org/show_bug.cgi?id=525962
Bug ID: 525962
Summary: Crash: null m_lockedItem dereferenced when placing
several Typewriter annotations in a row
(pageviewannotator.cpp:1154)
Classification: Applications
Product: okular
Version First unspecified
Reported In:
Platform: EndeavourOS
OS: Linux
Status: REPORTED
Severity: crash
Priority: NOR
Component: PDF backend
Assignee: [email protected]
Reporter: [email protected]
Target Milestone: ---
Created attachment 196377
--> https://bugs.kde.org/attachment.cgi?id=196377&action=edit
Combined debug info: package versions, live gdb backtrace (full symbols) and
core dump state (m_lockedItem = 0x0, PickPointEngine alive)
SUMMARY
Okular crashes with SIGSEGV when placing several Typewriter annotations one
after another. In PageViewAnnotator::performRouteMouseOrTabletEvent(), the loop
that attaches the newly created annotations to the page dereferences
m_lockedItem without a null check:
part/pageviewannotator.cpp:1154
m_document->addPageAnnotation(m_lockedItem->pageNumber(), annotation);
>From the core dump:
m_lockedItem = (PageViewItem *) 0x0
m_engine = valid PickPointEngine
m_engine->m_item = 0x0
m_creationCompleted = false
Both the annotator's locked item and the engine's own item pointer are null,
while the engine itself is still alive. The engine has already finished
creation and returned its annotations, so the crash happens at attach time,
not when the gesture starts.
STEPS TO REPRODUCE
1. Open any PDF document
2. Show the annotation toolbar (F6)
3. Select the "Typewriter" tool (Alt+5)
4. Click on the page, type some text, confirm the annotation
5. Immediately place another Typewriter annotation right next to the previous
one
6. Repeat step 5
OBSERVED RESULT
Okular crashes with SIGSEGV. The crash happens after 2 to 6 annotations -- the
exact count varies, but the crash itself is 100% reproducible: every single
attempt ends in a crash within a handful of annotations.
EXPECTED RESULT
Annotations are placed normally, no crash.
SOFTWARE/OS VERSIONS
Okular: 26.08.1
Operating System: Arch Linux (rolling, fully up to date, no partial upgrade)
Qt Version: 6.11.2-3
Graphics Platform: Wayland
ADDITIONAL INFORMATION
Crash occurs in the main thread while processing a mouse event; all other
threads are idle. Regardless of how m_lockedItem becomes null, the dereference
at line 1154 is unguarded and should be checked.
--
You are receiving this mail because:
You are watching all bug changes.