From 360d66cde79e7147356e10c8903e877fe192c2a9 Mon Sep 17 00:00:00 2001 From: nicm Date: Tue, 29 Sep 2026 11:57:28 +0000 Subject: [PATCH] Add a maximum repeat size as well as count. (cherry picked from commit 1bb90bdd628536d605357933916227cd314779ab) --- format.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/format.c b/format.c index 3456a823d..b9bf5e6d0 100644 --- a/format.c +++ b/format.c @@ -1,4 +1,4 @@ -/* $OpenBSD: format.c,v 1.421 2026/09/28 16:52:55 nicm Exp $ */ +/* $OpenBSD: format.c,v 1.422 2026/09/29 11:57:28 nicm Exp $ */ /* * Copyright (c) 2011 Nicholas Marriott @@ -88,9 +88,12 @@ format_job_cmp(struct format_job *fj1, struct format_job *fj2) /* Maximum pad and trim width. */ #define FORMAT_MAX_WIDTH 10000 -/* Maximum repeat size. */ +/* Maximum repeat count. */ #define FORMAT_MAX_REPEAT 10000 +/* Maximum repeat result size in bytes. */ +#define FORMAT_MAX_REPEAT_SIZE 65536 + /* Maximum precision. */ #define FORMAT_MAX_PRECISION 100 @@ -6427,7 +6430,7 @@ format_replace(struct format_expand_state *es, const char *key, size_t keylen, value = xstrdup(""); else { n = strlen(left); - if (n != 0 && nrep > (SIZE_MAX - 1) / n) { + if (n != 0 && nrep > FORMAT_MAX_REPEAT_SIZE / n) { format_log(es, "repeat is too long: %s", copy); value = xstrdup(""); } else {