From 1eab737e4d9d8515983ade034b906ffb88099c16 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Henrik=20Rydg=C3=A5rd?= Date: Sun, 9 Aug 2026 15:44:40 +0200 Subject: [PATCH] Serialize: guard List/Deque/Map/Set against corrupted size fields DoVector already rejects an attacker/corruption-controlled size that would resize far beyond what's actually left in the savestate buffer. DoList/DoDeque/DoMap/DoMultimap/DoSet never got the same treatment - a corrupted count field (e.g. 0xFFFFFFFF) drove an immediate huge resize (list/deque) or an unbounded loop of allocations (map/set) before any per-element bounds checking kicked in. All five now check the declared count against PointerWrap::Remaining() first. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY --- Common/Serialize/SerializeDeque.h | 7 +++++++ Common/Serialize/SerializeList.h | 7 +++++++ Common/Serialize/SerializeMap.h | 14 ++++++++++++++ Common/Serialize/SerializeSet.h | 6 ++++++ 4 files changed, 34 insertions(+) diff --git a/Common/Serialize/SerializeDeque.h b/Common/Serialize/SerializeDeque.h index d0dc8adbb0..3c9a817884 100644 --- a/Common/Serialize/SerializeDeque.h +++ b/Common/Serialize/SerializeDeque.h @@ -25,6 +25,13 @@ template void DoDeque(PointerWrap &p, std::deque &x, T &default_val) { u32 deq_size = (u32)x.size(); Do(p, deq_size); + // Guard against an attacker-controlled size driving a huge resize, same as DoVector. + if (p.mode == PointerWrap::MODE_READ || p.mode == PointerWrap::MODE_VERIFY) { + if (deq_size > p.Remaining() / sizeof(T)) { + p.SetError(PointerWrap::ERROR_FAILURE); + return; + } + } x.resize(deq_size, default_val); u32 i; for (i = 0; i < deq_size; i++) diff --git a/Common/Serialize/SerializeList.h b/Common/Serialize/SerializeList.h index 2a6fdcefa3..d344152fe8 100644 --- a/Common/Serialize/SerializeList.h +++ b/Common/Serialize/SerializeList.h @@ -25,6 +25,13 @@ template void DoList(PointerWrap &p, std::list &x, T &default_val) { u32 list_size = (u32)x.size(); Do(p, list_size); + // Guard against an attacker-controlled size driving a huge resize, same as DoVector. + if (p.mode == PointerWrap::MODE_READ || p.mode == PointerWrap::MODE_VERIFY) { + if (list_size > p.Remaining() / sizeof(T)) { + p.SetError(PointerWrap::ERROR_FAILURE); + return; + } + } x.resize(list_size, default_val); for (T &elem : x) diff --git a/Common/Serialize/SerializeMap.h b/Common/Serialize/SerializeMap.h index 294266b930..9c085b2cc2 100644 --- a/Common/Serialize/SerializeMap.h +++ b/Common/Serialize/SerializeMap.h @@ -29,6 +29,13 @@ void DoMap(PointerWrap &p, M &x, typename M::mapped_type &default_val) { switch (p.mode) { case PointerWrap::MODE_READ: { + // Guard against an attacker-controlled count driving an enormous number of + // loop iterations/allocations, same spirit as DoVector's guard. + constexpr size_t minElemSize = sizeof(typename M::key_type) + sizeof(typename M::mapped_type); + if (number > p.Remaining() / minElemSize) { + p.SetError(PointerWrap::ERROR_FAILURE); + return; + } x.clear(); while (number > 0) { typename M::key_type first = typename M::key_type(); @@ -100,6 +107,13 @@ void DoMultimap(PointerWrap &p, M &x, typename M::mapped_type &default_val) { switch (p.mode) { case PointerWrap::MODE_READ: { + // Guard against an attacker-controlled count driving an enormous number of + // loop iterations/allocations, same spirit as DoVector's guard. + constexpr size_t minElemSize = sizeof(typename M::key_type) + sizeof(typename M::mapped_type); + if (number > p.Remaining() / minElemSize) { + p.SetError(PointerWrap::ERROR_FAILURE); + return; + } x.clear(); while (number > 0) { typename M::key_type first = typename M::key_type(); diff --git a/Common/Serialize/SerializeSet.h b/Common/Serialize/SerializeSet.h index 286e285778..e555bd53ec 100644 --- a/Common/Serialize/SerializeSet.h +++ b/Common/Serialize/SerializeSet.h @@ -29,6 +29,12 @@ void DoSet(PointerWrap &p, std::set &x) { switch (p.mode) { case PointerWrap::MODE_READ: { + // Guard against an attacker-controlled count driving an enormous number of + // loop iterations/allocations, same spirit as DoVector's guard. + if (number > p.Remaining() / sizeof(T)) { + p.SetError(PointerWrap::ERROR_FAILURE); + return; + } x.clear(); while (number-- > 0) { T it = T();