improve emulator downloads with out of bounds checks

This commit is contained in:
iceman1001
2026-09-14 12:27:06 +02:00
parent 465deeda39
commit 8f5fd048d3
2 changed files with 29 additions and 6 deletions
+23
View File
@@ -3299,10 +3299,33 @@ static void PacketReceived(PacketCommandNG *packet) {
if (packet->length < sizeof(download_req_t)) {
break;
}
if (mem == NULL) {
reply_download_done(CMD_DOWNLOAD_EML_BIGBUF, 0, 0);
LED_B_OFF();
break;
}
const download_req_t *dreq = (const download_req_t *)packet->data.asBytes;
uint32_t startidx = dreq->start_index;
uint32_t numofbytes = dreq->bytes;
// We report the emulator memory size in capabilities_t, so honour it
// here as well. Without this a client asking for more than the
// emulator holds reads on past it into the rest of BigBuf
uint32_t em_size = BigBuf_get_EM_size();
if (startidx >= em_size) {
Dbprintf("Emulator memory download starts past the end, %u >= %u", startidx, em_size);
reply_download_done(CMD_DOWNLOAD_EML_BIGBUF, 0, 0);
LED_B_OFF();
break;
}
if (startidx + numofbytes > em_size) {
Dbprintf("Emulator memory is %u bytes, truncating download of %u to %u", em_size, numofbytes, em_size - startidx);
numofbytes = em_size - startidx;
}
// arg0 = startindex
// arg1 = length bytes to transfer
// arg2 = RFU
+6 -6
View File
@@ -2017,9 +2017,9 @@ static int CmdHFiClassESave(const char *Cmd) {
CLIParamStrToBuf(arg_get_str(ctx, 1), (uint8_t *)filename, FILE_PATH_SIZE, &fnlen);
uint16_t bytes = arg_get_int_def(ctx, 2, 256);
if (bytes > 4096) {
PrintAndLogEx(WARNING, "Emulator memory is max 4096bytes. Truncating %u to 4096", bytes);
bytes = 4096;
if (bytes > g_conn.em_size) {
PrintAndLogEx(WARNING, "Emulator memory is max %u bytes. Truncating %u to %u", g_conn.em_size, bytes, g_conn.em_size);
bytes = g_conn.em_size;
}
CLIParserFree(ctx);
@@ -2077,9 +2077,9 @@ static int CmdHFiClassEView(const char *Cmd) {
CLIParserFree(ctx);
if (bytes > 4096) {
PrintAndLogEx(WARNING, "Emulator memory is max 4096bytes. Truncating %u to 4096", bytes);
bytes = 4096;
if (bytes > g_conn.em_size) {
PrintAndLogEx(WARNING, "Emulator memory is max %u bytes. Truncating %u to %u", g_conn.em_size, bytes, g_conn.em_size);
bytes = g_conn.em_size;
}
if (bytes % 8 != 0) {