mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
libkmipclient: Fix integer overflow with large value length
Limit the value_len to not be larger than INT_MAX, because later on BIO_read() is called with value_len and it uses the int type for length parameter and return value. This check also prevents the 'value_len + 1' from overflow, because value_len is a size_t and this accepts larger values than int (even on 32 bit architectures). Assisted-by: IBM Bob:2.0.0 Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Reviewed-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
committed by
Jan Höppner
parent
7d56dde24a
commit
3ea90a2258
@@ -104,6 +104,11 @@ int kmip_decode_ttlv(BIO *bio, size_t *size, struct kmip_node **node,
|
||||
case KMIP_TYPE_TEXT_STRING:
|
||||
case KMIP_TYPE_BYTE_STRING:
|
||||
value_len = n->length;
|
||||
if (value_len > INT_MAX) {
|
||||
rc = -EMSGSIZE;
|
||||
goto out;
|
||||
}
|
||||
|
||||
value = calloc(1, value_len + 1);
|
||||
if (value == NULL) {
|
||||
kmip_debug(debug, "calloc failed");
|
||||
|
||||
Reference in New Issue
Block a user