From 9066afc0637d12a8b1beb50f1909b22d2d7779b7 Mon Sep 17 00:00:00 2001 From: xirvik Date: Mon, 17 Aug 2026 15:21:24 +0000 Subject: [PATCH] Guard the unit multiplication in value commands against overflow. The kb variants multiply the argument by 1024 without checking the range. --- src/rpc/command.cc | 10 +++++++++- src/rpc/parse.cc | 9 ++++++++- 2 files changed, 17 insertions(+), 2 deletions(-) diff --git a/src/rpc/command.cc b/src/rpc/command.cc index 0bd7da79..26c45b3c 100644 --- a/src/rpc/command.cc +++ b/src/rpc/command.cc @@ -1,5 +1,7 @@ #include "config.h" +#include + #include "core/download.h" #include "parse.h" @@ -41,7 +43,13 @@ command_base_call_value_base(command_base* command_raw, target_type target, cons return command_base::_call::type, T>(command_raw, target, val); } - return command_base::_call::type, T>(command_raw, target, unit * arg.as_value()); + auto value = arg.as_value(); + + if (value > std::numeric_limits::max() / unit || + value < std::numeric_limits::min() / unit) + throw torrent::input_error("Value out of range."); + + return command_base::_call::type, T>(command_raw, target, unit * value); } template const torrent::Object diff --git a/src/rpc/parse.cc b/src/rpc/parse.cc index 4bdaa6c7..e9407bdc 100644 --- a/src/rpc/parse.cc +++ b/src/rpc/parse.cc @@ -2,6 +2,7 @@ #include #include +#include #include #include @@ -136,7 +137,13 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) { // case ' ': // case '\0': *value = *value * unit; break; // default: throw torrent::input_error("Could not parse value."); - default: *value = *value * unit; break; + default: + if (*value > std::numeric_limits::max() / unit || + *value < std::numeric_limits::min() / unit) + return src; // overflow guard + + *value = *value * unit; + break; } return last;