escape: add a length check in curl_easy_escape - #20086
Closed
bagder wants to merge 2 commits into
Closed
Conversation
Only accept up to SIZE_MAX/16 input bytes. To avoid overflows, mistakes and abuse. Reported-by: Daniel Santos
There was a problem hiding this comment.
Pull request overview
This PR adds a length validation check to the curl_easy_escape function to prevent potential integer overflow and resource abuse. The change restricts input length to SIZE_MAX/16 before the allocation calculation that multiplies the length by 3.
Key Changes
- Add length validation to reject inputs larger than SIZE_MAX/16
- Return NULL for oversized inputs to prevent overflow in subsequent calculation
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Analysis of PR #20086 at 23afa3bb: Test 1501 failed, which has NOT been flaky recently, so there could be a real issue in this PR. Note that this test has failed in 12 different CI jobs (the link just goes to one of them). Generated by Testclutch |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Only accept up to SIZE_MAX/16 input bytes. To avoid overflows, mistakes and abuse.
Reported-by: Daniel Santos