mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
Serialize: guard List/Deque/Map/Set against corrupted size fields
DoVector already rejects an attacker/corruption-controlled size that would resize far beyond what's actually left in the savestate buffer. DoList/DoDeque/DoMap/DoMultimap/DoSet never got the same treatment - a corrupted count field (e.g. 0xFFFFFFFF) drove an immediate huge resize (list/deque) or an unbounded loop of allocations (map/set) before any per-element bounds checking kicked in. All five now check the declared count against PointerWrap::Remaining() first. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY
This commit is contained in:
1 parent
60796e08f9
commit
1eab737e4d
4 files changed
+34
No files matched your search
@@ -25,6 +25,13 @@ template<class T>
|
||||
void DoDeque(PointerWrap &p, std::deque<T> &x, T &default_val) {
|
||||
u32 deq_size = (u32)x.size();
|
||||
Do(p, deq_size);
|
||||
// Guard against an attacker-controlled size driving a huge resize, same as DoVector.
|
||||
if (p.mode == PointerWrap::MODE_READ || p.mode == PointerWrap::MODE_VERIFY) {
|
||||
if (deq_size > p.Remaining() / sizeof(T)) {
|
||||
p.SetError(PointerWrap::ERROR_FAILURE);
|
||||
return;
|
||||
}
|
||||
}
|
||||
x.resize(deq_size, default_val);
|
||||
u32 i;
|
||||
for (i = 0; i < deq_size; i++)
|
||||
|
||||
@@ -25,6 +25,13 @@ template<class T>
|
||||
void DoList(PointerWrap &p, std::list<T> &x, T &default_val) {
|
||||
u32 list_size = (u32)x.size();
|
||||
Do(p, list_size);
|
||||
// Guard against an attacker-controlled size driving a huge resize, same as DoVector.
|
||||
if (p.mode == PointerWrap::MODE_READ || p.mode == PointerWrap::MODE_VERIFY) {
|
||||
if (list_size > p.Remaining() / sizeof(T)) {
|
||||
p.SetError(PointerWrap::ERROR_FAILURE);
|
||||
return;
|
||||
}
|
||||
}
|
||||
x.resize(list_size, default_val);
|
||||
|
||||
for (T &elem : x)
|
||||
|
||||
@@ -29,6 +29,13 @@ void DoMap(PointerWrap &p, M &x, typename M::mapped_type &default_val) {
|
||||
switch (p.mode) {
|
||||
case PointerWrap::MODE_READ:
|
||||
{
|
||||
// Guard against an attacker-controlled count driving an enormous number of
|
||||
// loop iterations/allocations, same spirit as DoVector's guard.
|
||||
constexpr size_t minElemSize = sizeof(typename M::key_type) + sizeof(typename M::mapped_type);
|
||||
if (number > p.Remaining() / minElemSize) {
|
||||
p.SetError(PointerWrap::ERROR_FAILURE);
|
||||
return;
|
||||
}
|
||||
x.clear();
|
||||
while (number > 0) {
|
||||
typename M::key_type first = typename M::key_type();
|
||||
@@ -100,6 +107,13 @@ void DoMultimap(PointerWrap &p, M &x, typename M::mapped_type &default_val) {
|
||||
switch (p.mode) {
|
||||
case PointerWrap::MODE_READ:
|
||||
{
|
||||
// Guard against an attacker-controlled count driving an enormous number of
|
||||
// loop iterations/allocations, same spirit as DoVector's guard.
|
||||
constexpr size_t minElemSize = sizeof(typename M::key_type) + sizeof(typename M::mapped_type);
|
||||
if (number > p.Remaining() / minElemSize) {
|
||||
p.SetError(PointerWrap::ERROR_FAILURE);
|
||||
return;
|
||||
}
|
||||
x.clear();
|
||||
while (number > 0) {
|
||||
typename M::key_type first = typename M::key_type();
|
||||
|
||||
@@ -29,6 +29,12 @@ void DoSet(PointerWrap &p, std::set<T> &x) {
|
||||
switch (p.mode) {
|
||||
case PointerWrap::MODE_READ:
|
||||
{
|
||||
// Guard against an attacker-controlled count driving an enormous number of
|
||||
// loop iterations/allocations, same spirit as DoVector's guard.
|
||||
if (number > p.Remaining() / sizeof(T)) {
|
||||
p.SetError(PointerWrap::ERROR_FAILURE);
|
||||
return;
|
||||
}
|
||||
x.clear();
|
||||
while (number-- > 0) {
|
||||
T it = T();
|
||||
|
||||
Reference in new issue
Block a user