Files
Ben Levinsky d0e5e0d376 proxy: Validate retarget read response length
_read() converts the peer-provided unsigned data length to a signed
integer and bounds it only against the caller's buffer size. Large
values can bypass that comparison or make memcpy() read beyond the
fixed response buffer.

Reject nonpositive destination sizes, retain the peer length as an
unsigned value, and clamp it to both the response payload capacity and
the caller's buffer before copying.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
..
2016-02-09 11:55:45 -08:00