Skip to content

Validate Naomi link topology and RAM sizes - #2522

Open
acts-1631 wants to merge 1 commit into
flyinghead:masterfrom
acts-1631:fix/naomi-link-packet-validation
Open

acts-1631 wants to merge 1 commit into
flyinghead:masterfrom
acts-1631:fix/naomi-link-packet-validation

Conversation

@acts-1631

Copy link
Copy Markdown
Contributor

A Naomi link peer can advertise an excessive node count in a UDP Start packet:

slotCount = packet->start.nodeCount;

NaomiM3Comm::receiveNetwork later combines that count with the game’s communication slot size and copies the result into a fixed 128 KiB buffer:

const u32 packet_size = slot_size * slot_count;
memcpy(&comm_ram[0x100 + slot_size], buf.get(), packet_size);

The node count and destination range are not validated. With link networking enabled, a malicious peer can follow the forged Start packet with a Data packet and cause the copy to overwrite memory beyond comm_ram, crashing or corrupting Flycast.

Enforce each supported game’s configured node limit, validate SyncReply and Start topology data, and ignore Data packets received before the network starts. Also validate inbound and outbound communication-RAM layouts against the protocol’s packet limit and the fixed buffer capacity before accessing memory.

A link peer can advertise an excessive node count that later expands
a communication RAM copy beyond its fixed buffer.

Enforce the configured game topology, reject premature data packets,
and validate send and receive layouts before accessing communication
RAM.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant