[openssh-commits] [openssh] 04/06: upstream: Check that compressed payloads don't inflate beyond the

git+noreply at mindrot.org git+noreply at mindrot.org
Thu Oct 1 08:51:01 AEST 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit e0f85d83ccc15b1b218fa8a000fc29a2e3d2defd
Author: job at openbsd.org <job at openbsd.org>
AuthorDate: Tue Sep 22 22:51:43 2026 +0000

    upstream: Check that compressed payloads don't inflate beyond the
    
    maximum payload length
    
    From a report by Oleh Konko (1seal)
    
    OK djm@
    
    OpenBSD-Commit-ID: a0d3e7aa432777c28bfe23e5447ac117d6c151d9
---
 packet.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/packet.c b/packet.c
index 38a8c31bd..d63c579de 100644
--- a/packet.c
+++ b/packet.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: packet.c,v 1.345 2026/09/22 04:38:09 job Exp $ */
+/* $OpenBSD: packet.c,v 1.346 2026/09/22 22:51:43 job Exp $ */
 /*
  * Author: Tatu Ylonen <ylo at cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -913,6 +913,8 @@ uncompress_buffer(struct ssh *ssh, struct sshbuf *in, struct sshbuf *out)
 			if ((r = sshbuf_put(out, buf, sizeof(buf) -
 			    ssh->state->compression_in_stream.avail_out)) != 0)
 				return r;
+			if (sshbuf_len(out) >= PACKET_MAX_SIZE)
+				return SSH_ERR_INVALID_FORMAT;
 			break;
 		case Z_BUF_ERROR:
 			/*

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list