summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--send-stream.c8
1 files changed, 8 insertions, 0 deletions
diff --git a/send-stream.c b/send-stream.c
index 502e43ec..450854f6 100644
--- a/send-stream.c
+++ b/send-stream.c
@@ -82,6 +82,7 @@ static int read_cmd(struct btrfs_send_stream *sctx)
memset(sctx->cmd_attrs, 0, sizeof(sctx->cmd_attrs));
+ ASSERT(sizeof(*sctx->cmd_hdr) <= sizeof(sctx->read_buf));
ret = read_buf(sctx, sctx->read_buf, sizeof(*sctx->cmd_hdr));
if (ret < 0)
goto out;
@@ -95,6 +96,13 @@ static int read_cmd(struct btrfs_send_stream *sctx)
cmd = le16_to_cpu(sctx->cmd_hdr->cmd);
cmd_len = le32_to_cpu(sctx->cmd_hdr->len);
+ if (cmd_len + sizeof(*sctx->cmd_hdr) >= sizeof(sctx->read_buf)) {
+ ret = -EINVAL;
+ error("command length %d too big for buffer %zu",
+ cmd_len, sizeof(sctx->read_buf));
+ goto out;
+ }
+
data = sctx->read_buf + sizeof(*sctx->cmd_hdr);
ret = read_buf(sctx, data, cmd_len);
if (ret < 0)