mirror of
https://github.com/flatpak/flatpak.git
synced 2026-09-28 08:06:43 -04:00
delta_read_data computed g_malloc(size + 1) where size came from the delta stream. If size equals G_MAXSIZE, size + 1 wraps to zero and g_malloc returns a minimal allocation, then g_input_stream_read_all writes size bytes into it — a heap buffer overflow. Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc