Browse Source

fix etcp: infinite loop in feed_dgram_to_asm due to uint16_t overflow in new_cap doubling

chatgui
Evgeny 3 months ago
parent
commit
a2c7f1e6cb
  1. 9
      src/etcp.c

9
src/etcp.c

@ -70,7 +70,7 @@ static int inflight_seq_cmp(const void* a, const void* b) {
static void feed_dgram_to_asm(struct ETCP_CONN* etcp, struct PKTNORM* pn,
uint8_t* dgram, uint16_t dgram_len,
uint8_t** asm_buf, uint16_t* asm_len, uint16_t* asm_cap,
uint8_t** asm_buf, uint16_t* asm_len, uint32_t* asm_cap,
uint32_t* returned) {
uint32_t need = (uint32_t)*asm_len + dgram_len;
if (need >= ASM_BUF_MAX_SIZE) {
@ -78,9 +78,10 @@ static void feed_dgram_to_asm(struct ETCP_CONN* etcp, struct PKTNORM* pn,
return;
}
if (need > *asm_cap) {
uint16_t new_cap = *asm_cap ? *asm_cap : 256;
uint32_t new_cap = *asm_cap ? *asm_cap : 256;
while (new_cap < need) new_cap *= 2;
uint8_t* new_buf = u_realloc(*asm_buf, new_cap);
if (new_cap > 0xFFFF) new_cap = 0xFFFF;
uint8_t* new_buf = u_realloc(*asm_buf, (uint16_t)new_cap);
if (!new_buf) return;
*asm_buf = new_buf;
*asm_cap = new_cap;
@ -138,7 +139,7 @@ static void etcp_return_inflight_to_normalizer(struct ETCP_CONN* etcp) {
uint8_t* asm_buf = NULL;
uint16_t asm_len = 0;
uint16_t asm_cap = 0;
uint32_t asm_cap = 0;
uint32_t returned_packets = 0;
for (int i = 0; i < inflight_count; i++) {

Loading…
Cancel
Save