Files
DarkflameServer/dCommon
Aaron Kimbrell 8a2ccb1ae7 fix: bound AMF3 decoding and stop hashing client keys
Client-sent AMF (CONTROL_BEHAVIORS) was decoded without limits on the
associative part of arrays, on nesting depth, or on the total number of
values. Associative entries went into an unordered_map with the standard
unseeded string hash, so a client could pick colliding keys and make
insertion quadratic, and deeply nested arrays recursed until the stack
overflowed, crashing the world server.

- The associative map is now an ordered std::map (O(log n) whatever the
  keys, deterministic serialization order).
- Each array allows at most 10,000 associative entries, the same as the
  existing dense limit, which is now checked before anything is read.
- Arrays may nest at most 32 deep and one deserializer reads at most
  100,000 values. Every limit throws, which the only caller already
  catches and drops the message.
- Inserting a duplicate key keeps the last value and no longer returns a
  reference to a value that was destroyed when the key already held null.

Verified with new unit tests for each limit (including a 100,000 deep
nesting that previously overflowed the stack) and the existing live
packet test, which still decodes.

Fixes #2035

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:30:44 -05:00
..
2024-12-24 14:32:08 -08:00
2024-12-24 14:32:08 -08:00
2022-07-28 08:39:57 -05:00
2024-12-24 22:23:14 -08:00
2024-01-01 21:50:00 -06:00
2024-01-01 21:50:00 -06:00
2025-10-10 23:07:16 -05:00
2026-06-08 21:42:32 -07:00
2026-06-08 21:42:32 -07:00
2026-09-28 22:30:43 -05:00
2026-06-07 20:59:11 -07:00