From 8f5fd048d3a576a135a2707c700bab6d7da7dcc0 Mon Sep 17 00:00:00 2001 From: iceman1001 Date: Mon, 14 Sep 2026 12:27:06 +0200 Subject: [PATCH] improve emulator downloads with out of bounds checks --- armsrc/appmain.c | 23 +++++++++++++++++++++++ client/src/cmdhficlass.c | 12 ++++++------ 2 files changed, 29 insertions(+), 6 deletions(-) diff --git a/armsrc/appmain.c b/armsrc/appmain.c index 2f5d5476d..219bee189 100644 --- a/armsrc/appmain.c +++ b/armsrc/appmain.c @@ -3299,10 +3299,33 @@ static void PacketReceived(PacketCommandNG *packet) { if (packet->length < sizeof(download_req_t)) { break; } + + if (mem == NULL) { + reply_download_done(CMD_DOWNLOAD_EML_BIGBUF, 0, 0); + LED_B_OFF(); + break; + } + const download_req_t *dreq = (const download_req_t *)packet->data.asBytes; uint32_t startidx = dreq->start_index; uint32_t numofbytes = dreq->bytes; + // We report the emulator memory size in capabilities_t, so honour it + // here as well. Without this a client asking for more than the + // emulator holds reads on past it into the rest of BigBuf + uint32_t em_size = BigBuf_get_EM_size(); + if (startidx >= em_size) { + Dbprintf("Emulator memory download starts past the end, %u >= %u", startidx, em_size); + reply_download_done(CMD_DOWNLOAD_EML_BIGBUF, 0, 0); + LED_B_OFF(); + break; + } + + if (startidx + numofbytes > em_size) { + Dbprintf("Emulator memory is %u bytes, truncating download of %u to %u", em_size, numofbytes, em_size - startidx); + numofbytes = em_size - startidx; + } + // arg0 = startindex // arg1 = length bytes to transfer // arg2 = RFU diff --git a/client/src/cmdhficlass.c b/client/src/cmdhficlass.c index 306d5bd93..0d3a64263 100644 --- a/client/src/cmdhficlass.c +++ b/client/src/cmdhficlass.c @@ -2017,9 +2017,9 @@ static int CmdHFiClassESave(const char *Cmd) { CLIParamStrToBuf(arg_get_str(ctx, 1), (uint8_t *)filename, FILE_PATH_SIZE, &fnlen); uint16_t bytes = arg_get_int_def(ctx, 2, 256); - if (bytes > 4096) { - PrintAndLogEx(WARNING, "Emulator memory is max 4096bytes. Truncating %u to 4096", bytes); - bytes = 4096; + if (bytes > g_conn.em_size) { + PrintAndLogEx(WARNING, "Emulator memory is max %u bytes. Truncating %u to %u", g_conn.em_size, bytes, g_conn.em_size); + bytes = g_conn.em_size; } CLIParserFree(ctx); @@ -2077,9 +2077,9 @@ static int CmdHFiClassEView(const char *Cmd) { CLIParserFree(ctx); - if (bytes > 4096) { - PrintAndLogEx(WARNING, "Emulator memory is max 4096bytes. Truncating %u to 4096", bytes); - bytes = 4096; + if (bytes > g_conn.em_size) { + PrintAndLogEx(WARNING, "Emulator memory is max %u bytes. Truncating %u to %u", g_conn.em_size, bytes, g_conn.em_size); + bytes = g_conn.em_size; } if (bytes % 8 != 0) {