Guard the unit multiplication in value commands against overflow.

The kb variants multiply the argument by 1024 without checking the range.
This commit is contained in:
xirvik
2026-08-17 15:21:24 +00:00
committed by Jari Sundell
parent a2fabb10de
commit 9066afc063
2 changed files with 17 additions and 2 deletions
+8 -1
View File
@@ -2,6 +2,7 @@
#include <cstring>
#include <cstdio>
#include <limits>
#include <locale>
#include <torrent/exceptions.h>
@@ -136,7 +137,13 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
// case ' ':
// case '\0': *value = *value * unit; break;
// default: throw torrent::input_error("Could not parse value.");
default: *value = *value * unit; break;
default:
if (*value > std::numeric_limits<int64_t>::max() / unit ||
*value < std::numeric_limits<int64_t>::min() / unit)
return src; // overflow guard
*value = *value * unit;
break;
}
return last;