Skip to content

Fix Integer overflow in show_supplies() - #1715 - #1716

Open
PavlNekrasov wants to merge 1 commit into
OpenPrinting:masterfrom
PavlNekrasov:fix-integer-overflow-ippeveprinter-supply-level
Open

PavlNekrasov wants to merge 1 commit into
OpenPrinting:masterfrom
PavlNekrasov:fix-integer-overflow-ippeveprinter-supply-level

Conversation

@PavlNekrasov

Copy link
Copy Markdown

fixed #1715

Solution:
Clamped level to the 0..100 range declared by maxcapacity in printer-supply, both after reading the form field and after parsing it back out of printer-supply.

Signed-off-by: p.nekrasov@fobos-nt.ru
Signed-off-by: Timofei Fedotov sovtouch@altlinux.org

@michaelrsweet michaelrsweet self-assigned this Sep 24, 2026
@michaelrsweet michaelrsweet added the investigating Investigating the issue label Sep 24, 2026
@michaelrsweet

Copy link
Copy Markdown
Member

In the future, please combine bug report and PR into a single PR with the full explanation of the bug. Doing both just gives both of us extra work.

@michaelrsweet

Copy link
Copy Markdown
Member

Also, please start signing your commits...

Problem:
show_supplies() reads the supply level from the "supply%d" field of an unauthenticated GET request with atoi() and never range checks it. The value is stored in printer-supply, read back with atoi() and used as "level * 2", which overflows for both large negative and large positive levels.
Solution: Clamped level to the 0..100 range declared by maxcapacity in printer-supply, both after reading the form field and after parsing it back out of printer-supply.
Signed-off-by: p.nekrasov@fobos-nt.ru
Signed-off-by: Timofei Fedotov sovtouch@altlinux.org
@PavlNekrasov
PavlNekrasov force-pushed the fix-integer-overflow-ippeveprinter-supply-level branch from ac48555 to 97bcde0 Compare September 25, 2026 12:38
@PavlNekrasov

Copy link
Copy Markdown
Author

The commit has now been signed and forced-pushed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

investigating Investigating the issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Integer overflow in show_supplies()

2 participants