[openssh-commits] [openssh] 04/06: upstream: Check that compressed payloads don't inflate beyond the
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 08:51:01 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit e0f85d83ccc15b1b218fa8a000fc29a2e3d2defd
Author: job at openbsd.org <job at openbsd.org>
AuthorDate: Tue Sep 22 22:51:43 2026 +0000
upstream: Check that compressed payloads don't inflate beyond the
maximum payload length
From a report by Oleh Konko (1seal)
OK djm@
OpenBSD-Commit-ID: a0d3e7aa432777c28bfe23e5447ac117d6c151d9
---
packet.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/packet.c b/packet.c
index 38a8c31bd..d63c579de 100644
--- a/packet.c
+++ b/packet.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: packet.c,v 1.345 2026/09/22 04:38:09 job Exp $ */
+/* $OpenBSD: packet.c,v 1.346 2026/09/22 22:51:43 job Exp $ */
/*
* Author: Tatu Ylonen <ylo at cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -913,6 +913,8 @@ uncompress_buffer(struct ssh *ssh, struct sshbuf *in, struct sshbuf *out)
if ((r = sshbuf_put(out, buf, sizeof(buf) -
ssh->state->compression_in_stream.avail_out)) != 0)
return r;
+ if (sshbuf_len(out) >= PACKET_MAX_SIZE)
+ return SSH_ERR_INVALID_FORMAT;
break;
case Z_BUF_ERROR:
/*
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list