From 1c818866435dc84d6440d5c966d3c48bb8a9227b Mon Sep 17 00:00:00 2001 From: sithlord48 Date: Thu, 16 Apr 2026 07:23:15 -0400 Subject: [PATCH] fix: clipboard buffer overrun using propose solution from kitknox --- src/lib/deskflow/IClipboard.cpp | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/src/lib/deskflow/IClipboard.cpp b/src/lib/deskflow/IClipboard.cpp index 4b732ad2f..729ca1680 100644 --- a/src/lib/deskflow/IClipboard.cpp +++ b/src/lib/deskflow/IClipboard.cpp @@ -7,6 +7,8 @@ #include "deskflow/IClipboard.h" +#include "base/Log.h" + #include #include @@ -19,6 +21,7 @@ void IClipboard::unmarshall(IClipboard *clipboard, const std::string_view &data, assert(clipboard != nullptr); const char *index = data.data(); + const char *const end = index + data.size(); if (clipboard->open(time)) { // clear existing data @@ -26,10 +29,20 @@ void IClipboard::unmarshall(IClipboard *clipboard, const std::string_view &data, // read the number of formats const uint32_t numFormats = readUInt32(index); + if (end - index < 4) { + LOG_ERR("clipboard unmarshall: truncated header"); + clipboard->close(); + return; + } index += 4; // read each format for (uint32_t i = 0; i < numFormats; ++i) { + // need 8 bytes for format id + payload size + if (end - index < 8) { + LOG_ERR("clipboard unmarshall: truncated format header at %u/%u", i, numFormats); + break; + } // get the format id auto format = static_cast(readUInt32(index)); index += 4; @@ -38,6 +51,12 @@ void IClipboard::unmarshall(IClipboard *clipboard, const std::string_view &data, uint32_t size = readUInt32(index); index += 4; + // peer-supplied size must not exceed remaining buffer + if (size > static_cast(end - index)) { + LOG_ERR("clipboard unmarshall: payload size %u exceeds remaining %zd", size, end - index); + break; + } + // save the data if it's a known format. if either the client // or server supports more clipboard formats than the other // then one of them will get a format >= TotalFormats here.