diff --git a/modules/core/src/copy.cpp b/modules/core/src/copy.cpp index aab4fbd3f0..d641c6f497 100644 --- a/modules/core/src/copy.cpp +++ b/modules/core/src/copy.cpp @@ -860,14 +860,14 @@ void copyMakeBorder_8u( const uchar* src, size_t srcstep, cv::Size srcroi, } dstroi.width *= elemSize; - dst += dststep*top; for( i = 0; i < top; i++ ) { j = cv::borderInterpolate(i - top, srcroi.height, borderType); - memcpy(dst + (i - top)*dststep, dst + j*dststep, dstroi.width); + memcpy(dst + i*dststep, dst + (top+j)*dststep, dstroi.width); } + dst += dststep*top; for( i = 0; i < bottom; i++ ) { j = cv::borderInterpolate(i + srcroi.height, srcroi.height, borderType); diff --git a/modules/core/src/matrix.cpp b/modules/core/src/matrix.cpp index 8111dc2230..513e13ea5f 100644 --- a/modules/core/src/matrix.cpp +++ b/modules/core/src/matrix.cpp @@ -1128,7 +1128,7 @@ Mat& Mat::adjustROI( int dtop, int dbottom, int dleft, int dright ) if(col1 > col2) std::swap(col1, col2); - data += (row1 - ofs.y)*step + (col1 - ofs.x)*esz; + data += (row1 - ofs.y)*(std::ptrdiff_t)step + (col1 - ofs.x)*(std::ptrdiff_t)esz; rows = row2 - row1; cols = col2 - col1; size.p[0] = rows; size.p[1] = cols; updateContinuityFlag(); diff --git a/modules/core/test/test_mat.cpp b/modules/core/test/test_mat.cpp index aea0507149..f476118f65 100644 --- a/modules/core/test/test_mat.cpp +++ b/modules/core/test/test_mat.cpp @@ -1368,6 +1368,18 @@ TEST(Core_Mat, copyNx1ToVector) ASSERT_PRED_FORMAT2(cvtest::MatComparator(0, 0), ref_dst16, cv::Mat_(dst16)); } +TEST(Core_Mat, copyMakeBoderUndefinedBehavior) +{ + Mat1b src(4, 4), dst; + randu(src, Scalar(10), Scalar(100)); + // This could trigger a (signed int)*size_t operation which is undefined behavior. + cv::copyMakeBorder(src, dst, 1, 1, 1, 1, cv::BORDER_REFLECT_101); + EXPECT_EQ(0, cv::norm(src.row(1), dst(Rect(1,0,4,1)))); + EXPECT_EQ(0, cv::norm(src.row(2), dst(Rect(1,5,4,1)))); + EXPECT_EQ(0, cv::norm(src.col(1), dst(Rect(0,1,1,4)))); + EXPECT_EQ(0, cv::norm(src.col(2), dst(Rect(5,1,1,4)))); +} + TEST(Core_Matx, fromMat_) { Mat_ a = (Mat_(2,2) << 10, 11, 12, 13); diff --git a/modules/core/test/test_operations.cpp b/modules/core/test/test_operations.cpp index 934028f3ae..5158e65bda 100644 --- a/modules/core/test/test_operations.cpp +++ b/modules/core/test/test_operations.cpp @@ -1379,6 +1379,15 @@ TEST(MatTestRoi, adjustRoiOverflow) ASSERT_EQ(roi.rows, m.rows); } +TEST(MatTestRoi, adjustRoiUndefinedBehavior) +{ + Mat m(6, 6, CV_8U); + Mat roi(m, cv::Range(2, 4), cv::Range(2, 4)); + // This could trigger a (negative int)*size_t when updating data, + // which is undefined behavior. + roi.adjustROI(2, 2, 2, 2); + EXPECT_EQ(m.data, roi.data); +} CV_ENUM(SortRowCol, SORT_EVERY_COLUMN, SORT_EVERY_ROW) CV_ENUM(SortOrder, SORT_ASCENDING, SORT_DESCENDING)