]> git.ipfire.org Git - thirdparty/sqlite.git/commitdiff
Prevent a malicious delta from causing an integer overflow in the
authordrh <>
Thu, 11 Dec 2025 23:24:05 +0000 (23:24 +0000)
committerdrh <>
Thu, 11 Dec 2025 23:24:05 +0000 (23:24 +0000)
fossildelta extension.  This code is not used in the SQLite core.

FossilOrigin-Name: 01409738afc2c0d5bdaa248ffb508aa5f36a66390f6b8e4834734529ee8ed2fa

ext/misc/fossildelta.c
ext/rbu/sqlite3rbu.c
manifest
manifest.uuid

index d24a87700e476cb618dad245c22b4501cbe377d9..b9ff27c532baead6f7fabb88744e5dc794387399 100644 (file)
@@ -38,9 +38,11 @@ SQLITE_EXTENSION_INIT1
 
 #ifndef SQLITE_AMALGAMATION
 /*
-** The "u32" type must be an unsigned 32-bit integer.  Adjust this
+** The "u32" type must be an unsigned 32-bit integer.  "u64" is
+** an unsigned 64-bit integer.
 */
 typedef unsigned int u32;
+typedef sqlite3_uint64 u64;
 
 /*
 ** Must be a 16-bit value
@@ -570,7 +572,7 @@ static int delta_apply(
           /* ERROR: copy exceeds output file size */
           return -1;
         }
-        if( ofst+cnt > lenSrc ){
+        if( (u64)ofst+(u64)cnt > (u64)lenSrc ){
           /* ERROR: copy extends past end of input */
           return -1;
         }
index 4509986ee7b69405bdace34bf1631addbbb06f5c..e3bcd5fc79487ea3f602ad4bff4f37d41ab65aae 100644 (file)
@@ -623,7 +623,7 @@ static int rbuDeltaApply(
           /* ERROR: copy exceeds output file size */
           return -1;
         }
-        if( (int)(ofst+cnt) > lenSrc ){
+        if( (u64)ofst+(u64)cnt > (u64)lenSrc ){
           /* ERROR: copy extends past end of input */
           return -1;
         }
index 547a61abc2baf609a4fc098f1e90fb30fb8210c1..6baf35d15235127fa375d84b76dacb955225f00a 100644 (file)
--- a/manifest
+++ b/manifest
@@ -1,5 +1,5 @@
-C Update\sbuild\sinstructions\sfor\sWindows\sto\sexplain\show\sto\slink\sagainst\nZLIB.
-D 2025-12-11T18:16:39.432
+C Prevent\sa\smalicious\sdelta\sfrom\scausing\san\sinteger\soverflow\sin\sthe\nfossildelta\sextension.\s\sThis\scode\sis\snot\sused\sin\sthe\sSQLite\score.
+D 2025-12-11T23:24:05.667
 F .fossil-settings/binary-glob 61195414528fb3ea9693577e1980230d78a1f8b0a54c78cf1b9b24d0a409ed6a x
 F .fossil-settings/empty-dirs dbb81e8fc0401ac46a1491ab34a7f2c7c0452f2f06b54ebb845d024ca8283ef1
 F .fossil-settings/ignore-glob 35175cdfcf539b2318cb04a9901442804be81cd677d8b889fcc9149c21f239ea
@@ -373,7 +373,7 @@ F ext/misc/decimal.c d4883de142f6dcd36eda23da40b55e2b51374e7b01eb54a717394019138
 F ext/misc/eval.c 04bc9aada78c888394204b4ed996ab834b99726fb59603b0ee3ed6e049755dc1
 F ext/misc/explain.c 606100185fb90d6a1eade1ed0414d53503c86820d8956a06e3b0a56291894f2b
 F ext/misc/fileio.c 452300ca34fadafd2bb9eb09557de5a518da1fd2349f9f9cedd22b1566a7164f
-F ext/misc/fossildelta.c 2fc2dd4f34f478df674887db62586b1071c4cd3c9e73ee40f9ee669670e482d1
+F ext/misc/fossildelta.c 547d0b6744dbec531f081a8c52daf302c38d72da5f548307ee8f72a6618ff419
 F ext/misc/fuzzer.c 6b231352815304ba60d8e9ec2ee73d4918e74d9b76bda8940ba2b64e8777515e
 F ext/misc/ieee754.c 176c061c94857b543313959289cb60cf777c999fd002f82b53d194b95e9f347a
 F ext/misc/memstat.c 43705d795090efb78c85c736b89251e743c291e23daaa8382fe7a0df2c6a283d
@@ -464,7 +464,7 @@ F ext/rbu/rbuvacuum.test 542561741ff2b262e3694bc6012b44694ee62c545845319a06f3237
 F ext/rbu/rbuvacuum2.test 1a9bd41f127be2826de2a65204df9118525a8af8d16e61e6bc63ba3ac0010a23
 F ext/rbu/rbuvacuum3.test 3ce42695fdf21aaa3499e857d7d4253bc499ad759bcd6c9362042c13cd37d8de
 F ext/rbu/rbuvacuum4.test ffccd22f67e2d0b380d2889685742159dfe0d19a3880ca3d2d1d69eefaebb205
-F ext/rbu/sqlite3rbu.c c208f72f20784bf2f39244b6cdf8019724a706e1246be289e7621c42aad54695
+F ext/rbu/sqlite3rbu.c 3fb2390575b261c365d3f6fea61ff15e74d5d89e373f2a2bfa4d80c24321e793
 F ext/rbu/sqlite3rbu.h e3a5bf21e09ca93ce4e8740e00d6a853e90a697968ec0ea98f40826938bdb68e
 F ext/rbu/test_rbu.c 8b6e64e486c28c41ef29f6f4ea6be7b3091958987812784904f5e903f6b56418
 F ext/recover/dbdata.c 10d3c56968a9af6853722a47280805ad1564714d79ea45ac6f7da14bb57fd137
@@ -2184,8 +2184,8 @@ F tool/version-info.c 33d0390ef484b3b1cb685d59362be891ea162123cea181cb8e6d2cf6dd
 F tool/warnings-clang.sh bbf6a1e685e534c92ec2bfba5b1745f34fb6f0bc2a362850723a9ee87c1b31a7
 F tool/warnings.sh d924598cf2f55a4ecbc2aeb055c10bd5f48114793e7ba25f9585435da29e7e98
 F tool/win/sqlite.vsix deb315d026cc8400325c5863eef847784a219a2f
-P ba003c7c74fb4dd665a8ec6dea7d030f1e7e9cbb13e60bb728860ebffdff5aaf
-R 1c99cad3fd8583fa54bc224ab3f05c00
+P e785a80e4100c368dca8d73cb662cff4d0fd76734fa0f3fa9b5754a380f7c746
+R d97187709711ac6befc9df59998f577d
 U drh
-Z c4c875edc56563f1723c026f14c53914
+Z a79d44db71901fb1ea2f28a2ac813d65
 # Remove this line to create a well-formed Fossil manifest.
index 427688d1c0e4dcd7b5c4b0cdf03f52ff44b03377..5be08de9b7dee1088535f098418fd5ce1006254d 100644 (file)
@@ -1 +1 @@
-e785a80e4100c368dca8d73cb662cff4d0fd76734fa0f3fa9b5754a380f7c746
+01409738afc2c0d5bdaa248ffb508aa5f36a66390f6b8e4834734529ee8ed2fa