Blame SOURCES/libtar-1.2.20-CVE-2021-33643-CVE-2021-33644.patch

dc7088
From 3936c7aa74d89e7a91dfbb2c1b7bfcad58a0355d Mon Sep 17 00:00:00 2001
dc7088
From: shixuantong <1726671442@qq.com>
dc7088
Date: Wed, 6 Apr 2022 17:40:57 +0800
dc7088
Subject: [PATCH 1/2] Ensure that sz is greater than 0.
dc7088
dc7088
---
dc7088
 lib/block.c | 10 ++++++++++
dc7088
 1 file changed, 10 insertions(+)
dc7088
dc7088
diff --git a/lib/block.c b/lib/block.c
dc7088
index 092bc28..f12c4bc 100644
dc7088
--- a/lib/block.c
dc7088
+++ b/lib/block.c
dc7088
@@ -118,6 +118,11 @@ th_read(TAR *t)
dc7088
 	if (TH_ISLONGLINK(t))
dc7088
 	{
dc7088
 		sz = th_get_size(t);
dc7088
+		if ((int)sz <= 0)
dc7088
+		{
dc7088
+			errno = EINVAL;
dc7088
+			return -1;
dc7088
+		}
dc7088
 		blocks = (sz / T_BLOCKSIZE) + (sz % T_BLOCKSIZE ? 1 : 0);
dc7088
 		if (blocks > ((size_t)-1 / T_BLOCKSIZE))
dc7088
 		{
dc7088
@@ -168,6 +173,11 @@ th_read(TAR *t)
dc7088
 	if (TH_ISLONGNAME(t))
dc7088
 	{
dc7088
 		sz = th_get_size(t);
dc7088
+		if ((int)sz <= 0)
dc7088
+		{
dc7088
+			errno = EINVAL;
dc7088
+			return -1;
dc7088
+		}
dc7088
 		blocks = (sz / T_BLOCKSIZE) + (sz % T_BLOCKSIZE ? 1 : 0);
dc7088
 		if (blocks > ((size_t)-1 / T_BLOCKSIZE))
dc7088
 		{
dc7088
-- 
dc7088
2.37.1
dc7088