fix: resolve all security issues (#154, #156, #157, #159, #160, #161, #162, #170)
CI / lint (pull_request) Failing after 3s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
CI / lint (pull_request) Failing after 3s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
#include "delta.h"
|
||||
#include "log.h"
|
||||
#include <stdint.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
|
||||
@@ -7,6 +8,10 @@
|
||||
#define XXH_IMPLEMENTATION
|
||||
#include <xxhash.h>
|
||||
|
||||
/* Maximum number of blocks/instructions allowed from the wire to prevent OOM */
|
||||
#define MAX_DELTA_BLOCKS (1024U * 1024U) /* 1M signature blocks */
|
||||
#define MAX_DELTA_INSTRUCTIONS (1024U * 1024U) /* 1M delta instructions */
|
||||
|
||||
uint32_t delta_adler32(const void* data, uint32_t len) {
|
||||
const uint8_t* p = (const uint8_t*)data;
|
||||
uint32_t s1 = 1;
|
||||
@@ -101,6 +106,14 @@ DeltaSignature* delta_signature_deserialize(const Data* data) {
|
||||
memcpy(&sig->block_count, buf + pos, sizeof(uint32_t));
|
||||
pos += sizeof(uint32_t);
|
||||
|
||||
// Reject unreasonably large block counts to prevent OOM
|
||||
if (sig->block_count > MAX_DELTA_BLOCKS) {
|
||||
log_message(LOG_LEVEL_ERROR, "Delta signature block count %u exceeds maximum %u",
|
||||
sig->block_count, MAX_DELTA_BLOCKS);
|
||||
free(sig);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
uint64_t expected = sizeof(uint64_t) + sizeof(uint32_t) + sizeof(uint32_t) +
|
||||
(uint64_t)sig->block_count * (sizeof(uint32_t) + sizeof(uint32_t));
|
||||
if (data->size < expected) {
|
||||
@@ -340,6 +353,14 @@ Delta* delta_deserialize(const Data* data) {
|
||||
memcpy(&delta->instruction_count, buf + pos, sizeof(uint32_t));
|
||||
pos += sizeof(uint32_t);
|
||||
|
||||
// Reject unreasonably large instruction counts to prevent OOM
|
||||
if (delta->instruction_count > MAX_DELTA_INSTRUCTIONS) {
|
||||
log_message(LOG_LEVEL_ERROR, "Delta instruction count %u exceeds maximum %u",
|
||||
delta->instruction_count, MAX_DELTA_INSTRUCTIONS);
|
||||
free(delta);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
delta->instructions = malloc(delta->instruction_count * sizeof(DeltaInstruction));
|
||||
if (!delta->instructions) {
|
||||
free(delta);
|
||||
|
||||
Reference in New Issue
Block a user