mirror of
https://github.com/veracrypt/VeraCrypt.git
synced 2026-10-05 16:46:35 -05:00
Merge commit from fork
* Harden serializer deserialization bounds * Finalize Unix serializer hardening Validate object types before parsing and release owned objects on failure. Enforce nesting limits through shared serialization entry points. Mirror read/write size limits and reject embedded NULs while preserving the wire format. Add regression tests for bounds, types, and cleanup. Validated Linux self-tests, C++03 platform tests, and ASan/UBSan with leak detection. Co-authored-by: Damian Rickard <damian@rickard.us> --------- Co-authored-by: Damian Rickard <damian@rickard.us> Co-authored-by: Mounir IDRASSI <mounir.idrassi@amcrypto.jp>
This commit is contained in:
25 files changed
+738
-171
No files matched your search
@@ -136,18 +136,18 @@ namespace VeraCrypt
|
||||
|
||||
#ifdef TC_HEADER_Platform_Exception
|
||||
|
||||
void PCSCException::Deserialize(shared_ptr <Stream> stream)
|
||||
void PCSCException::DeserializeData(shared_ptr <Stream> stream)
|
||||
{
|
||||
Exception::Deserialize(stream);
|
||||
Exception::DeserializeData(stream);
|
||||
Serializer sr(stream);
|
||||
int64 v;
|
||||
sr.Deserialize("ErrorCode", v);
|
||||
ErrorCode = (LONG_PCSC)v;
|
||||
}
|
||||
|
||||
void PCSCException::Serialize(shared_ptr <Stream> stream) const
|
||||
void PCSCException::SerializeData(shared_ptr <Stream> stream) const
|
||||
{
|
||||
Exception::Serialize(stream);
|
||||
Exception::SerializeData(stream);
|
||||
Serializer sr(stream);
|
||||
int64 v = (int64)ErrorCode;
|
||||
sr.Serialize("ErrorCode", v);
|
||||
@@ -176,17 +176,17 @@ namespace VeraCrypt
|
||||
|
||||
#ifdef TC_HEADER_Platform_Exception
|
||||
|
||||
void CommandAPDUNotValid::Deserialize(shared_ptr <Stream> stream)
|
||||
void CommandAPDUNotValid::DeserializeData(shared_ptr <Stream> stream)
|
||||
{
|
||||
Exception::Deserialize(stream);
|
||||
Exception::DeserializeData(stream);
|
||||
Serializer sr(stream);
|
||||
sr.Deserialize("SrcPos", SrcPos);
|
||||
sr.Deserialize("ErrorStr", ErrorStr);
|
||||
}
|
||||
|
||||
void CommandAPDUNotValid::Serialize(shared_ptr <Stream> stream) const
|
||||
void CommandAPDUNotValid::SerializeData(shared_ptr <Stream> stream) const
|
||||
{
|
||||
Exception::Serialize(stream);
|
||||
Exception::SerializeData(stream);
|
||||
Serializer sr(stream);
|
||||
sr.Serialize("SrcPos", SrcPos);
|
||||
sr.Serialize("ErrorStr", ErrorStr);
|
||||
|
||||
Reference in new issue
Block a user