Apply limits to the transfer lengths. At least in the case where a one byte FTDI
header is used that only has 6 bits of length info this would've previously potentially overflowed depending on the input size. git-svn-id: file:///srv/svn/repos/haiku/haiku/trunk@42088 a95241bf-73f2-0310-859d-f6bbb57e9c96
This commit is contained in:
@@ -225,9 +225,12 @@ FTDIDevice::OnRead(char **buffer, size_t *numBytes)
|
|||||||
void
|
void
|
||||||
FTDIDevice::OnWrite(const char *buffer, size_t *numBytes, size_t *packetBytes)
|
FTDIDevice::OnWrite(const char *buffer, size_t *numBytes, size_t *packetBytes)
|
||||||
{
|
{
|
||||||
|
if (*numBytes > FTDI_BUFFER_SIZE)
|
||||||
|
*numBytes = *packetBytes = FTDI_BUFFER_SIZE;
|
||||||
|
|
||||||
char *writeBuffer = WriteBuffer();
|
char *writeBuffer = WriteBuffer();
|
||||||
if (fHeaderLength > 0) {
|
if (fHeaderLength > 0) {
|
||||||
if (*numBytes >= WriteBufferSize() - fHeaderLength)
|
if (*numBytes > WriteBufferSize() - fHeaderLength)
|
||||||
*numBytes = *packetBytes = WriteBufferSize() - fHeaderLength;
|
*numBytes = *packetBytes = WriteBufferSize() - fHeaderLength;
|
||||||
|
|
||||||
*writeBuffer = FTDI_OUT_TAG(*numBytes, FTDI_PIT_DEFAULT);
|
*writeBuffer = FTDI_OUT_TAG(*numBytes, FTDI_PIT_DEFAULT);
|
||||||
|
|||||||
@@ -149,7 +149,10 @@ KLSIDevice::OnRead(char **buffer, size_t *numBytes)
|
|||||||
void
|
void
|
||||||
KLSIDevice::OnWrite(const char *buffer, size_t *numBytes, size_t *packetBytes)
|
KLSIDevice::OnWrite(const char *buffer, size_t *numBytes, size_t *packetBytes)
|
||||||
{
|
{
|
||||||
if (*numBytes >= WriteBufferSize() - 2)
|
if (*numBytes > KLSI_BUFFER_SIZE)
|
||||||
|
*numBytes = *packetBytes = KLSI_BUFFER_SIZE;
|
||||||
|
|
||||||
|
if (*numBytes > WriteBufferSize() - 2)
|
||||||
*numBytes = *packetBytes = WriteBufferSize() - 2;
|
*numBytes = *packetBytes = WriteBufferSize() - 2;
|
||||||
|
|
||||||
char *writeBuffer = WriteBuffer();
|
char *writeBuffer = WriteBuffer();
|
||||||
|
|||||||
Reference in New Issue
Block a user