From 9c05451fa81d6ad4962479f86f643b173dfe1f70 Mon Sep 17 00:00:00 2001 From: JacobBarthelmeh Date: Wed, 29 Jul 2026 10:47:46 -0600 Subject: [PATCH] SFTP client sanity check on version used by the server --- src/wolfsftp.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/src/wolfsftp.c b/src/wolfsftp.c index 1783ffa43..5f5aed1fc 100644 --- a/src/wolfsftp.c +++ b/src/wolfsftp.c @@ -6374,6 +6374,16 @@ static int SFTP_ClientRecvInit(WOLFSSH* ssh) { } ato32(buf + LENGTH_SZ + MSG_ID_SZ, &version); + /* The server is supposed to reply with the lower of its own and + * our version, so a value above ours is a non-conforming server. In + * that case we continue on with the same v3 version. If the server + * replies with a version before v3 then return early here since + * there will be SSH_FXP_STATUS incompatibility issues. */ + if (version < WOLFSSH_SFTP_VERSION) { + WLOG(WS_LOG_SFTP, "Unsupported SFTP version from server"); + return WS_VERSION_E; + } + sz = sz - MSG_ID_SZ - UINT32_SZ; ssh->sftpExtSz = sz; ssh->sftpState = SFTP_EXT;