瀏覽代碼

Fix heap overflow from curl-originating buffers

Most of xs.h seems to expect that buffers are rounded up to block size,
so we should preserve that invariant here. (In particular, xs_expand
will avoid calling xs_realloc if the new size fits in the same block,
which means that if we don't pad out the data it will expand out of the
memory we're allocated.)
Saagar Jha 3 年之前
父節點
當前提交
ea9c030249
共有 1 個文件被更改,包括 1 次插入1 次删除
  1. 1 1
      xs_curl.h

+ 1 - 1
xs_curl.h

@@ -55,7 +55,7 @@ static int _data_callback(void *buffer, size_t size,
 
 
     /* open space */
     /* open space */
     pd->size += sz;
     pd->size += sz;
-    pd->data = xs_realloc(pd->data, pd->size + 1);
+    pd->data = xs_realloc(pd->data, _xs_blk_size(pd->size + 1));
 
 
     /* copy data */
     /* copy data */
     memcpy(pd->data + pd->offset, buffer, sz);
     memcpy(pd->data + pd->offset, buffer, sz);