Merge commit from fork

`read_packet()` passed a peer-supplied `Content-Length` straight to
`switch_zmalloc(body, clen + 1)`. Huge values drove `calloc` failure
and `switch_zmalloc` `abort()`-ed the daemon.

- Cap `Content-Length` at 16 MiB; reject negatives.
- Destroy the partially-built `*event` at the new rejection site and
at the existing body-recv failure path so callers don't leak it.
- Add `test_mod_event_socket` covering `INT_MAX`, above-cap,
negative, `atoi`-overflow, zero, and valid-non-zero-body cases.
This commit is contained in:
Dmitry Verenitsin
2026-08-08 17:48:05 +03:00
committed by GitHub
parent a38cd80733
commit a097e12421
5 changed files with 414 additions and 0 deletions
+1
View File
@@ -7,6 +7,7 @@ noinst_PROGRAMS += switch_stun
noinst_PROGRAMS += test_tts_format
noinst_PROGRAMS+= switch_hold switch_sip
noinst_PROGRAMS += test_mod_verto
noinst_PROGRAMS += test_mod_event_socket
if HAVE_PCAP
noinst_PROGRAMS += switch_rtp_pcap