In delta_signature_deserialize(), sig->block_count comes from the network. The allocation malloc(sig->block_count * sizeof(DeltaBlockSig)) at delta.c:111 can overflow if block_count is large enough (e.g., > 536M on 64-bit), leading to a small allocation but subsequent out-of-bounds writes.
Location
src/shared/delta.c:111
How to trigger
Send a crafted delta signature with a very large block_count field. The multiplication overflows, causing a small allocation. Subsequent writes in the loop write past the buffer.
This issue was automatically generated by the issue-creator agent.
## Description
In `delta_signature_deserialize()`, `sig->block_count` comes from the network. The allocation `malloc(sig->block_count * sizeof(DeltaBlockSig))` at delta.c:111 can overflow if `block_count` is large enough (e.g., > 536M on 64-bit), leading to a small allocation but subsequent out-of-bounds writes.
## Location
src/shared/delta.c:111
## How to trigger
Send a crafted delta signature with a very large `block_count` field. The multiplication overflows, causing a small allocation. Subsequent writes in the loop write past the buffer.
## Suggested Fix
Add overflow check before allocation:
```
if (sig->block_count > SIZE_MAX / sizeof(DeltaBlockSig)) {
free(sig);
return NULL;
}
```
## Severity
high
## Category
security
## Sub-Agent
security-screener (SC-3)
---
_This issue was automatically generated by the issue-creator agent._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
delta_signature_deserialize(),sig->block_countcomes from the network. The allocationmalloc(sig->block_count * sizeof(DeltaBlockSig))at delta.c:111 can overflow ifblock_countis large enough (e.g., > 536M on 64-bit), leading to a small allocation but subsequent out-of-bounds writes.Location
src/shared/delta.c:111
How to trigger
Send a crafted delta signature with a very large
block_countfield. The multiplication overflows, causing a small allocation. Subsequent writes in the loop write past the buffer.Suggested Fix
Add overflow check before allocation:
Severity
high
Category
security
Sub-Agent
security-screener (SC-3)
This issue was automatically generated by the issue-creator agent.
Fixed in PR #148 — merged into main on 2026-07-29. See #148