dir: Fix integer overflow in read_fd on 32-bit platforms

st_size is a 64-bit off_t but was truncated to gsize which is
32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would
cause size + 1 to overflow to 0, leading to a zero-size allocation
followed by an oversized read.
This commit is contained in:
Sebastian Wick committed 2026-07-27 13:41:00 +00:00
1 parent 6950a22bf4
commit fa794f166c
1 file changed
+7
+7
View File
@@ -8172,6 +8172,13 @@ read_fd (int fd,
gsize size;
gsize alloc_size;
if (stat_buf->st_size < 0 || (guint64) stat_buf->st_size > G_MAXSIZE - 1)
{
g_set_error_literal (error, G_FILE_ERROR, G_FILE_ERROR_NOMEM,
_("Not enough memory"));
return FALSE;
}
size = stat_buf->st_size;
alloc_size = size + 1;