mirror of
https://github.com/flatpak/flatpak.git
synced 2026-09-23 13:46:07 -04:00
oci: Limit delta path length to PATH_MAX
The previous commit ensures that there isn't a heap overflow when reading a huge delta path, but we should also just reject unreasonably long paths. So we chose the arbitrary limit of PATH_MAX and assume that anything beyond that arbitrary limit is probably abusive. Helps: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
This commit is contained in:
1 parent
c52e851f3f
commit
f710ca12a0
1 file changed
+15
-10
@@ -2130,8 +2130,6 @@ flatpak_oci_registry_apply_delta_stream (FlatpakOciRegistry *self,
|
||||
{
|
||||
guint8 op;
|
||||
gsize size;
|
||||
g_autofree char *path = NULL;
|
||||
g_autofree char *clean_path = NULL;
|
||||
g_autoptr(GError) local_error = NULL;
|
||||
gboolean eof;
|
||||
|
||||
@@ -2154,22 +2152,29 @@ flatpak_oci_registry_apply_delta_stream (FlatpakOciRegistry *self,
|
||||
break;
|
||||
|
||||
case DELTA_OP_OPEN:
|
||||
path = (char *)delta_read_data (in, size, cancellable, error);
|
||||
if (path == NULL)
|
||||
return FALSE;
|
||||
clean_path = delta_clean_path (path);
|
||||
|
||||
g_clear_object (&content_file);
|
||||
|
||||
{
|
||||
g_autoptr(GFile) child = g_file_resolve_relative_path (content_dir, clean_path);
|
||||
g_autofree char *path = NULL;
|
||||
g_autofree char *clean_path = NULL;
|
||||
g_autoptr(GFile) child = NULL;
|
||||
g_autoptr(GFileInputStream) child_in = NULL;
|
||||
|
||||
if (size > PATH_MAX)
|
||||
return flatpak_fail (error, _("Invalid delta file format"));
|
||||
|
||||
path = (char *) delta_read_data (in, size, cancellable, error);
|
||||
if (path == NULL)
|
||||
return FALSE;
|
||||
|
||||
clean_path = delta_clean_path (path);
|
||||
|
||||
child = g_file_resolve_relative_path (content_dir, clean_path);
|
||||
|
||||
child_in = g_file_read (child, cancellable, error);
|
||||
if (child_in == NULL)
|
||||
return FALSE;
|
||||
|
||||
/* We can't seek in the ostree repo file, so copy it to temp file */
|
||||
g_clear_object (&content_file);
|
||||
content_file = copy_stream_to_file (self, G_INPUT_STREAM (child_in), cancellable, error);
|
||||
if (content_file == NULL)
|
||||
return FALSE;
|
||||
|
||||
Reference in new issue
Block a user