diff --git a/src/engine/engine_io.c b/src/engine/engine_io.c index 6d65f2e6..e5f0b952 100644 --- a/src/engine/engine_io.c +++ b/src/engine/engine_io.c @@ -35,6 +35,8 @@ #pragma warning (disable: 4305) // disable MSVC warning: truncation from 'double' to 'float' #endif +static const int MAX_ARRAY_SIZE = INT_MAX / 4; + //------------------------------ mjLROpt ----------------------------------------------------------- // set default options for length range computation @@ -454,7 +456,7 @@ mjModel* mj_makeModel(int nq, int nv, int nu, int na, int nbody, int njnt, } // nmocap is going to get multiplied by 4, and shouldn't overflow - if (m->nmocap >= INT_MAX / 4) { + if (m->nmocap >= MAX_ARRAY_SIZE) { mju_free(m); mju_warning("Invalid model: nmocap too large"); return 0; @@ -1405,6 +1407,9 @@ const char* mj_validateReferences(const mjModel* m) { if (num < 0) { \ return "Invalid model: " #numarray " is negative."; \ } \ + if (num > MAX_ARRAY_SIZE) { \ + return "Invalid model: " #numarray " is too large."; \ + } \ int adrsmax = m->adrarray[i] + num; \ if (adrsmax > m->ntarget || adrsmin < -1) { \ return "Invalid model: " #adrarray " out of bounds."; \