mime.c: avoid integer overflow in base64 size calculation

Reported-by: xmoezzz on github
Fixes #22320
Closes #22322
This commit is contained in:
Daniel Stenberg 2026-07-14 08:52:21 +02:00
parent 6546ffeda4
commit bc440a89d4
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2

View file

@ -419,6 +419,11 @@ static size_t encoder_base64_read(char *buffer, size_t size, bool ateof,
return cursize;
}
/* The maximum input size that does not cause an overflow. */
#define BASE64_MAX_INPUT_SIZE \
(((CURL_OFF_T_MAX / (MAX_ENCODED_LINE_LENGTH + 2)) * \
MAX_ENCODED_LINE_LENGTH / 4) * 3 - 3)
static curl_off_t encoder_base64_size(curl_mimepart *part)
{
curl_off_t size = part->datasize;
@ -426,6 +431,10 @@ static curl_off_t encoder_base64_size(curl_mimepart *part)
if(size <= 0)
return size; /* Unknown size or no data. */
/* Prevent integer overflows */
if(size > BASE64_MAX_INPUT_SIZE)
return -1;
/* Compute base64 character count. */
size = 4 * (1 + ((size - 1) / 3));