CVE-2026-33986: Premature Dimension Update Before Allocation

A state object's dimensions (width/height) are updated before a memory allocation loop that could fail and exit. If an allocation fails, the function returns early and leaves the context dimensions inflated for a smaller buffer. This inconsistency can lead to out-of-bounds memory accesses. Update object dimensional properties only after validating that memor

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-33986-premature-dimension-update-before-allocation --engine opengrep

Description

A state object's dimensions (width/height) are updated before a memory allocation loop that could fail and exit. If an allocation fails, the function returns early and leaves the context dimensions inflated for a smaller buffer. This inconsistency can lead to out-of-bounds memory accesses. Update object dimensional properties only after validating that memor