ZSTD_getFrameContentSize() returns unsigned long long, but it is assigned to size_t on 32-bit platforms, where size_t is 32 bits. If a compressed frame has a decompressed size larger than 4GB, the value will be truncated.
Additionally, the decompression loop grows the buffer by doubling (line 83: buf_size *= 2), which can quickly exhaust memory on 32-bit systems.
Location
src/shared/compression.c:48-63
Suggested Fix
Validate that dst_size fits in size_t before using it:
## Description
In `src/shared/compression.c` lines 48-49:
```c
unsigned long long dst_size =
ZSTD_getFrameContentSize(compressed_data->data, compressed_data->size);
// ...
size_t buf_size =
(!ZSTD_isError(dst_size) && dst_size > 0) ? (size_t)dst_size : INITIAL_DECOMPRESS_BUF_SIZE;
```
`ZSTD_getFrameContentSize()` returns `unsigned long long`, but it is assigned to `size_t` on 32-bit platforms, where `size_t` is 32 bits. If a compressed frame has a decompressed size larger than 4GB, the value will be truncated.
Additionally, the decompression loop grows the buffer by doubling (line 83: `buf_size *= 2`), which can quickly exhaust memory on 32-bit systems.
## Location
`src/shared/compression.c:48-63`
## Suggested Fix
Validate that `dst_size` fits in `size_t` before using it:
```c
unsigned long long dst_size_raw =
ZSTD_getFrameContentSize(compressed_data->data, compressed_data->size);
if (!ZSTD_isError(dst_size_raw) && dst_size_raw > 0) {
if (dst_size_raw > SIZE_MAX) {
log_message(LOG_LEVEL_ERROR, "Decompressed size exceeds address space");
return NULL;
}
buf_size = (size_t)dst_size_raw;
}
```
## Severity
Low
## Category
Bug
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
In
src/shared/compression.clines 48-49:ZSTD_getFrameContentSize()returnsunsigned long long, but it is assigned tosize_ton 32-bit platforms, wheresize_tis 32 bits. If a compressed frame has a decompressed size larger than 4GB, the value will be truncated.Additionally, the decompression loop grows the buffer by doubling (line 83:
buf_size *= 2), which can quickly exhaust memory on 32-bit systems.Location
src/shared/compression.c:48-63Suggested Fix
Validate that
dst_sizefits insize_tbefore using it:Severity
Low
Category
Bug