|
| 1 | +From 487e062de90850689f14ca3d55cbdb9088d41bde Mon Sep 17 00:00:00 2001 |
| 2 | +From: Philip Withnall <pwithnall@gnome.org> |
| 3 | +Date: Tue, 25 Nov 2025 19:02:56 +0000 |
| 4 | +Subject: [PATCH] gvariant-parser: Fix potential integer overflow parsing |
| 5 | + (byte)strings |
| 6 | + |
| 7 | +The termination condition for parsing string and bytestring literals in |
| 8 | +GVariant text format input was subject to an integer overflow for input |
| 9 | +string (or bytestring) literals longer than `INT_MAX`. |
| 10 | + |
| 11 | +Fix that by counting as a `size_t` rather than as an `int`. The counter |
| 12 | +can never correctly be negative. |
| 13 | + |
| 14 | +Spotted by treeplus. Thanks to the Sovereign Tech Resilience programme |
| 15 | +from the Sovereign Tech Agency. ID: #YWH-PGM9867-145 |
| 16 | + |
| 17 | +Signed-off-by: Philip Withnall <pwithnall@gnome.org> |
| 18 | +Fixes: #3834 |
| 19 | +Signed-off-by: Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> |
| 20 | +Upstream-reference: https://gitlab.gnome.org/GNOME/glib/-/commit/3e72fe0fbb32c18a66486c4da8bc851f656af287.patch |
| 21 | +--- |
| 22 | + glib/gvariant-parser.c | 10 +++++----- |
| 23 | + 1 file changed, 5 insertions(+), 5 deletions(-) |
| 24 | + |
| 25 | +diff --git a/glib/gvariant-parser.c b/glib/gvariant-parser.c |
| 26 | +index bb5238b..af6527d 100644 |
| 27 | +--- a/glib/gvariant-parser.c |
| 28 | ++++ b/glib/gvariant-parser.c |
| 29 | +@@ -594,7 +594,7 @@ ast_resolve (AST *ast, |
| 30 | + { |
| 31 | + GVariant *value; |
| 32 | + gchar *pattern; |
| 33 | +- gint i, j = 0; |
| 34 | ++ size_t i, j = 0; |
| 35 | + |
| 36 | + pattern = ast_get_pattern (ast, error); |
| 37 | + |
| 38 | +@@ -1555,9 +1555,9 @@ string_free (AST *ast) |
| 39 | + * No leading/trailing space allowed. */ |
| 40 | + static gboolean |
| 41 | + unicode_unescape (const gchar *src, |
| 42 | +- gint *src_ofs, |
| 43 | ++ size_t *src_ofs, |
| 44 | + gchar *dest, |
| 45 | +- gint *dest_ofs, |
| 46 | ++ size_t *dest_ofs, |
| 47 | + gsize length, |
| 48 | + SourceRef *ref, |
| 49 | + GError **error) |
| 50 | +@@ -1618,7 +1618,7 @@ string_parse (TokenStream *stream, |
| 51 | + gsize length; |
| 52 | + gchar quote; |
| 53 | + gchar *str; |
| 54 | +- gint i, j; |
| 55 | ++ size_t i, j; |
| 56 | + |
| 57 | + token_stream_start_ref (stream, &ref); |
| 58 | + token = token_stream_get (stream); |
| 59 | +@@ -1748,7 +1748,7 @@ bytestring_parse (TokenStream *stream, |
| 60 | + gsize length; |
| 61 | + gchar quote; |
| 62 | + gchar *str; |
| 63 | +- gint i, j; |
| 64 | ++ size_t i, j; |
| 65 | + |
| 66 | + token_stream_start_ref (stream, &ref); |
| 67 | + token = token_stream_get (stream); |
| 68 | +-- |
| 69 | +2.45.4 |
| 70 | + |
0 commit comments