Merge commit from fork

* Harden serializer deserialization bounds

* Finalize Unix serializer hardening

Validate object types before parsing and release owned objects on failure.
Enforce nesting limits through shared serialization entry points.

Mirror read/write size limits and reject embedded NULs while preserving
the wire format. Add regression tests for bounds, types, and cleanup.

Validated Linux self-tests, C++03 platform tests, and ASan/UBSan with leak
detection.

Co-authored-by: Damian Rickard <damian@rickard.us>

---------

Co-authored-by: Damian Rickard <damian@rickard.us>
Co-authored-by: Mounir IDRASSI <mounir.idrassi@amcrypto.jp>
This commit is contained in:
authored and GitHub committed 2026-09-30 20:12:20 +09:00
1 parent dea8fb0dc0
commit fb9d96c52d
25 files changed
+738 -171

No files matched your search

+2 -3
View File
@@ -16,7 +16,7 @@
namespace VeraCrypt
{
void VolumeInfo::Deserialize (shared_ptr <Stream> stream)
void VolumeInfo::DeserializeData (shared_ptr <Stream> stream)
{
Serializer sr (stream);
@@ -63,9 +63,8 @@ namespace VeraCrypt
return first->SerialInstanceNumber > second->SerialInstanceNumber;
}
void VolumeInfo::Serialize (shared_ptr <Stream> stream) const
void VolumeInfo::SerializeData (shared_ptr <Stream> stream) const
{
Serializable::Serialize (stream);
Serializer sr (stream);
const uint32 version = VERSION_NUM;
+6 -3
View File
@@ -36,11 +36,13 @@ namespace VeraCrypt
PasswordBuffer.Allocate (MaxSize);
}
void VolumePassword::Deserialize (shared_ptr <Stream> stream)
void VolumePassword::DeserializeData (shared_ptr <Stream> stream)
{
Serializer sr (stream);
uint64 passwordSize;
sr.Deserialize ("PasswordSize", passwordSize);
if (passwordSize > MaxSize)
throw ParameterIncorrect (SRC_POS);
PasswordSize = static_cast <size_t> (passwordSize);
sr.Deserialize ("PasswordBuffer", BufferPtr (PasswordBuffer));
@@ -48,9 +50,10 @@ namespace VeraCrypt
sr.Deserialize ("WipeData", wipeBuffer);
}
void VolumePassword::Serialize (shared_ptr <Stream> stream) const
void VolumePassword::SerializeData (shared_ptr <Stream> stream) const
{
Serializable::Serialize (stream);
if (PasswordSize > MaxSize)
throw ParameterIncorrect (SRC_POS);
Serializer sr (stream);
sr.Serialize ("PasswordSize", static_cast <uint64> (PasswordSize));
sr.Serialize ("PasswordBuffer", ConstBufferPtr (PasswordBuffer));