From fa794f166cf727b0bc70bf116259776b7da08685 Mon Sep 17 00:00:00 2001 From: Sebastian Wick Date: Tue, 30 Jun 2026 22:00:53 +0200 Subject: [PATCH] dir: Fix integer overflow in read_fd on 32-bit platforms st_size is a 64-bit off_t but was truncated to gsize which is 32-bit on 32-bit platforms. A file larger than G_MAXSIZE - 1 would cause size + 1 to overflow to 0, leading to a zero-size allocation followed by an oversized read. --- common/flatpak-dir.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/common/flatpak-dir.c b/common/flatpak-dir.c index 8f2813cc2..b139a8027 100644 --- a/common/flatpak-dir.c +++ b/common/flatpak-dir.c @@ -8172,6 +8172,13 @@ read_fd (int fd, gsize size; gsize alloc_size; + if (stat_buf->st_size < 0 || (guint64) stat_buf->st_size > G_MAXSIZE - 1) + { + g_set_error_literal (error, G_FILE_ERROR, G_FILE_ERROR_NOMEM, + _("Not enough memory")); + return FALSE; + } + size = stat_buf->st_size; alloc_size = size + 1;