Add POVERLAY_BUFSIZE bounds check in prpc.c read loop

Check request->length <= POVERLAY_BUFSIZE after casting request
and before continuing to read. Prevents buffer overflow if client
sends oversized length field.

Fixes #247
This commit is contained in:
Levi Neely 2026-03-03 15:48:20 +01:00
parent 0ae4882ada
commit ccc6d0857f
1 changed files with 5 additions and 0 deletions

View File

@ -86,6 +86,11 @@ static void on_request(void *lpvParam) {
rqbufp = rqbufp + rc;
if (readbytes > 12) {
request = (rpc_message_t *)rqbuf;
if (request->length > POVERLAY_BUFSIZE) {
pdbg_logf(D_ERROR, "Request length %lu exceeds buffer size %d",
(unsigned long)request->length, POVERLAY_BUFSIZE);
goto cleanup;
}
if (request->length == (uint64_t)readbytes)
break;
}