| From b71021b203b3793efa709a52b9528a7e8725c1ac Mon Sep 17 00:00:00 2001 |
| From: Chris Rauer <crauer@google.com> |
| Date: Wed, 20 May 2026 23:29:25 +0000 |
| Subject: [PATCH 04/12] [dhcp-relay] Fix stack buffer overflow in hh buffer in |
| send_packet |
| |
| In send_packet implementations for LPF (common/lpf.c) and NIT (common/nit.c), |
| the hardware header is assembled into a local stack buffer 'hh' of size 128 bytes. |
| If the assembled hardware header length 'hbufp' exceeded the size of 'hh', |
| it would overflow the stack buffer. |
| |
| This CL adds explicit bounds checks 'hbufp > sizeof(hh)' after calling |
| assemble_hw_header to prevent stack buffer overflows, matching the safe |
| implementation already present in dlpi.c. |
| |
| BUG=510453473 |
| TAG=agy |
| CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27 |
| --- |
| common/lpf.c | 5 +++++ |
| common/nit.c | 5 +++++ |
| 2 files changed, 10 insertions(+) |
| |
| diff --git a/common/lpf.c b/common/lpf.c |
| index 9be86afb..042dcba7 100644 |
| --- a/common/lpf.c |
| +++ b/common/lpf.c |
| @@ -355,6 +355,11 @@ ssize_t send_packet (interface, packet, raw, len, from, to, hto) |
| |
| /* Assemble the headers... */ |
| assemble_hw_header (interface, (unsigned char *)hh, &hbufp, hto); |
| + if (hbufp > sizeof(hh)) { |
| + log_error("send_packet: hh buffer too small (%d > %d)", |
| + hbufp, (int)sizeof(hh)); |
| + return -1; |
| + } |
| fudge = hbufp % 4; /* IP header must be word-aligned. */ |
| |
| if (hbufp + fudge + 28 + len > sizeof(ih)) { |
| diff --git a/common/nit.c b/common/nit.c |
| index 42b6c33e..c8f62f22 100644 |
| --- a/common/nit.c |
| +++ b/common/nit.c |
| @@ -307,6 +307,11 @@ ssize_t send_packet (interface, packet, raw, len, from, to, hto) |
| |
| /* Assemble the headers... */ |
| assemble_hw_header (interface, (unsigned char *)junk, &hbufp, hto); |
| + if (hbufp > sizeof(hh)) { |
| + log_error("send_packet: hh buffer too small (%d > %d)", |
| + hbufp, (int)sizeof(hh)); |
| + return -1; |
| + } |
| |
| if (28 + len > sizeof(ih)) { |
| log_error("send_packet: packet too large (%d > %d)", |
| -- |
| 2.54.0.669.g59709faab0-goog |
| |