blob: 6e98a23e7ffbad28860fdbc326cf5a2ea6d14b26 [file]
From b71021b203b3793efa709a52b9528a7e8725c1ac Mon Sep 17 00:00:00 2001
From: Chris Rauer <crauer@google.com>
Date: Wed, 20 May 2026 23:29:25 +0000
Subject: [PATCH 04/12] [dhcp-relay] Fix stack buffer overflow in hh buffer in
send_packet
In send_packet implementations for LPF (common/lpf.c) and NIT (common/nit.c),
the hardware header is assembled into a local stack buffer 'hh' of size 128 bytes.
If the assembled hardware header length 'hbufp' exceeded the size of 'hh',
it would overflow the stack buffer.
This CL adds explicit bounds checks 'hbufp > sizeof(hh)' after calling
assemble_hw_header to prevent stack buffer overflows, matching the safe
implementation already present in dlpi.c.
BUG=510453473
TAG=agy
CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27
---
common/lpf.c | 5 +++++
common/nit.c | 5 +++++
2 files changed, 10 insertions(+)
diff --git a/common/lpf.c b/common/lpf.c
index 9be86afb..042dcba7 100644
--- a/common/lpf.c
+++ b/common/lpf.c
@@ -355,6 +355,11 @@ ssize_t send_packet (interface, packet, raw, len, from, to, hto)
/* Assemble the headers... */
assemble_hw_header (interface, (unsigned char *)hh, &hbufp, hto);
+ if (hbufp > sizeof(hh)) {
+ log_error("send_packet: hh buffer too small (%d > %d)",
+ hbufp, (int)sizeof(hh));
+ return -1;
+ }
fudge = hbufp % 4; /* IP header must be word-aligned. */
if (hbufp + fudge + 28 + len > sizeof(ih)) {
diff --git a/common/nit.c b/common/nit.c
index 42b6c33e..c8f62f22 100644
--- a/common/nit.c
+++ b/common/nit.c
@@ -307,6 +307,11 @@ ssize_t send_packet (interface, packet, raw, len, from, to, hto)
/* Assemble the headers... */
assemble_hw_header (interface, (unsigned char *)junk, &hbufp, hto);
+ if (hbufp > sizeof(hh)) {
+ log_error("send_packet: hh buffer too small (%d > %d)",
+ hbufp, (int)sizeof(hh));
+ return -1;
+ }
if (28 + len > sizeof(ih)) {
log_error("send_packet: packet too large (%d > %d)",
--
2.54.0.669.g59709faab0-goog