From 2f01b482586295071079a26ef64ec7d58ecdf8a2 Mon Sep 17 00:00:00 2001 From: NK Date: Tue, 17 Mar 2026 02:16:51 +0100 Subject: [PATCH] Validate GPT entry size before allocation and slice access Reject entry_size outside 128-4096 range to prevent: - panic on slice &entry[0..16] when entry_size < 16 - OOM allocation from forged u32 entry_size GPT spec mandates minimum 128 bytes per partition entry. --- src/sam/partition.rs | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/src/sam/partition.rs b/src/sam/partition.rs index 0fd7575..e33a28d 100644 --- a/src/sam/partition.rs +++ b/src/sam/partition.rs @@ -82,6 +82,14 @@ fn find_gpt_ntfs_partitions(reader: &mut R) -> Result> let num_entries = crate::utils::read_u32_le(&hdr, 0x50).unwrap_or(0); let entry_size = crate::utils::read_u32_le(&hdr, 0x54).unwrap_or(0); + // GPT spec: entry_size is typically 128 bytes; reject invalid values + if !(128..=4096).contains(&entry_size) { + return Err(crate::error::VmkatzError::DecryptionError(format!( + "Invalid GPT entry size: {} (expected 128-4096)", + entry_size, + ))); + } + log::debug!( "GPT: entry_lba={}, num_entries={}, entry_size={}", entry_lba,