mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
ReadFrame() accepted a 64-bit client-supplied payload length with only a top-bit check, and ReadPending() immediately resized a buffer by it before any data had arrived - a single frame claiming a huge length (reachable via the WebSocket debugger endpoint) could trigger a multi-exabyte allocation attempt. Now rejected up front (both the single frame and the fragmented-message total) against a 64MB cap. Also replaced &payload[0]/&vector[0] with .data() in the send/receive paths - operator[] on a possibly-empty vector (e.g. an empty PING) is UB even when the result is never dereferenced. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY