From a7bfa15144c0107001b3a9fa9f1f76121f803d4b Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 16 Jul 2026 10:21:06 -1000 Subject: Bound the authenticate-post length safely The POST length was clamped with a signed comparison, so a very large Content-Length could turn negative and slip past the limit into the fixed-size buffer. --- source/cgit.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) (limited to 'source/cgit.c') diff --git a/source/cgit.c b/source/cgit.c index 74e80a6..d636d2d 100644 --- a/source/cgit.c +++ b/source/cgit.c @@ -699,15 +699,16 @@ static inline void open_auth_filter(const char *function) static inline void authenticate_post(void) { char buffer[MAX_AUTHENTICATION_POST_BYTES]; - ssize_t len; + size_t len; + ssize_t got; open_auth_filter("authenticate-post"); len = ctx.env.content_length; if (len > MAX_AUTHENTICATION_POST_BYTES) len = MAX_AUTHENTICATION_POST_BYTES; - if ((len = read(STDIN_FILENO, buffer, len)) < 0) + if ((got = read(STDIN_FILENO, buffer, len)) < 0) die_errno("Could not read POST from stdin"); - if (write(STDOUT_FILENO, buffer, len) < 0) + if (write(STDOUT_FILENO, buffer, got) < 0) die_errno("Could not write POST to stdout"); cgit_close_filter(ctx.cfg.auth_filter); exit(0); -- cgit v2.8.0