9beba4b
diff -up thunderbird-91.7.0/parser/expat/lib/xmlparse.c.expat-CVE-2022-25315 thunderbird-91.7.0/parser/expat/lib/xmlparse.c
9beba4b
--- thunderbird-91.7.0/parser/expat/lib/xmlparse.c.expat-CVE-2022-25315	2022-03-02 18:17:50.966583254 +0100
9beba4b
+++ thunderbird-91.7.0/parser/expat/lib/xmlparse.c	2022-03-02 18:19:27.636924735 +0100
9beba4b
@@ -2479,6 +2479,7 @@ storeRawNames(XML_Parser parser)
9beba4b
   while (tag) {
9beba4b
     int bufSize;
9beba4b
     int nameLen = sizeof(XML_Char) * (tag->name.strLen + 1);
9beba4b
+    size_t rawNameLen;
9beba4b
     char *rawNameBuf = tag->buf + nameLen;
9beba4b
     /* Stop if already stored.  Since tagStack is a stack, we can stop
9beba4b
        at the first entry that has already been copied; everything
9beba4b
@@ -2490,7 +2491,11 @@ storeRawNames(XML_Parser parser)
9beba4b
     /* For re-use purposes we need to ensure that the
9beba4b
        size of tag->buf is a multiple of sizeof(XML_Char).
9beba4b
     */
9beba4b
-    bufSize = nameLen + ROUND_UP(tag->rawNameLength, sizeof(XML_Char));
9beba4b
+    rawNameLen = ROUND_UP(tag->rawNameLength, sizeof(XML_Char));
9beba4b
+    /* Detect and prevent integer overflow. */
9beba4b
+    if (rawNameLen > (size_t)INT_MAX - nameLen)
9beba4b
+      return XML_FALSE;
9beba4b
+    bufSize = nameLen + (int)rawNameLen;
9beba4b
     if (bufSize > tag->bufEnd - tag->buf) {
9beba4b
       char *temp = (char *)REALLOC(tag->buf, bufSize);
9beba4b
       if (temp == NULL)