| From 37d307c52612504381f51dcbce440c431eaa225c Mon Sep 17 00:00:00 2001 |
| From: Chris Rauer <crauer@google.com> |
| Date: Wed, 20 May 2026 23:32:59 +0000 |
| Subject: [PATCH 05/12] [dhcp-relay] Fix stack buffer overflow and integer |
| underflow in concat_dclists |
| |
| In concat_dclists (common/tree.c), two compressed domain lists (list1 and list2) |
| are uncompressed into a local stack buffer 'uncompbuf' of size 32 * NS_MAXCDNAME. |
| |
| A vulnerability existed where, if the first list uncompressed to exactly fill |
| the buffer (uncomp_len == sizeof(uncompbuf)), the code would still attempt to |
| append a comma separator: |
| 1. Writing the comma byte out of bounds (1-byte stack buffer overflow). |
| 2. Incrementing uncomp_len to sizeof(uncompbuf) + 1. |
| 3. Underflowing the remaining space calculation: (sizeof(uncompbuf) - uncomp_len) |
| which wrapped to a huge positive value when passed as 'size_t dst_size' |
| to the second uncompress call, potentially causing a larger stack overflow. |
| |
| This CL fixes the vulnerability by adding an explicit bounds check: |
| 'uncomp_len >= sizeof(uncompbuf) - 1' before attempting to append the comma. |
| If there is no space for the comma and at least a portion of the second list, |
| it logs an error and returns 0. |
| |
| BUG=510454983 |
| TAG=agy |
| CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27 |
| --- |
| common/tree.c | 4 ++++ |
| 1 file changed, 4 insertions(+) |
| |
| diff --git a/common/tree.c b/common/tree.c |
| index 68173354..5cf635c3 100644 |
| --- a/common/tree.c |
| +++ b/common/tree.c |
| @@ -4204,6 +4204,10 @@ int concat_dclists (struct data_string* result, |
| if (list2 && (list2->data) && (list2->len)) { |
| /* If first list wasn't empty, add a comma */ |
| if (uncomp_len > 0) { |
| + if (uncomp_len >= sizeof(uncompbuf) - 1) { |
| + log_error("concat_dclists: no space for comma"); |
| + return (0); |
| + } |
| *uncomp++ = ','; |
| uncomp_len++; |
| } |
| -- |
| 2.54.0.669.g59709faab0-goog |
| |