mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-08-31 17:55:23 +02:00
DoVector already rejects an attacker/corruption-controlled size that would resize far beyond what's actually left in the savestate buffer. DoList/DoDeque/DoMap/DoMultimap/DoSet never got the same treatment - a corrupted count field (e.g. 0xFFFFFFFF) drove an immediate huge resize (list/deque) or an unbounded loop of allocations (map/set) before any per-element bounds checking kicked in. All five now check the declared count against PointerWrap::Remaining() first. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY
52 lines
1.5 KiB
C++
52 lines
1.5 KiB
C++
// Copyright (C) 2003 Dolphin Project.
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU General Public License as published by
|
|
// the Free Software Foundation, version 2.0 or later versions.
|
|
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License 2.0 for more details.
|
|
|
|
// A copy of the GPL 2.0 should have been included with the program.
|
|
// If not, see http://www.gnu.org/licenses/
|
|
|
|
// Official SVN repository and contact information can be found at
|
|
// http://code.google.com/p/dolphin-emu/
|
|
|
|
#pragma once
|
|
|
|
// Templates for save state serialization. See Serializer.h.
|
|
#include <deque>
|
|
#include "Common/Serialize/SerializeFuncs.h"
|
|
|
|
template<class T>
|
|
void DoDeque(PointerWrap &p, std::deque<T> &x, T &default_val) {
|
|
u32 deq_size = (u32)x.size();
|
|
Do(p, deq_size);
|
|
// Guard against an attacker-controlled size driving a huge resize, same as DoVector.
|
|
if (p.mode == PointerWrap::MODE_READ || p.mode == PointerWrap::MODE_VERIFY) {
|
|
if (deq_size > p.Remaining() / sizeof(T)) {
|
|
p.SetError(PointerWrap::ERROR_FAILURE);
|
|
return;
|
|
}
|
|
}
|
|
x.resize(deq_size, default_val);
|
|
u32 i;
|
|
for (i = 0; i < deq_size; i++)
|
|
Do(p, x[i]);
|
|
}
|
|
|
|
template<class T>
|
|
void Do(PointerWrap &p, std::deque<T *> &x) {
|
|
T *dv = nullptr;
|
|
DoDeque(p, x, dv);
|
|
}
|
|
|
|
template<class T>
|
|
void Do(PointerWrap &p, std::deque<T> &x) {
|
|
T dv = T();
|
|
DoDeque(p, x, dv);
|
|
}
|