blob: ff8d9c2ad4470bc3cb2b61f8de9c97f72e68c4cf [file]
From 37d307c52612504381f51dcbce440c431eaa225c Mon Sep 17 00:00:00 2001
From: Chris Rauer <crauer@google.com>
Date: Wed, 20 May 2026 23:32:59 +0000
Subject: [PATCH 05/12] [dhcp-relay] Fix stack buffer overflow and integer
underflow in concat_dclists
In concat_dclists (common/tree.c), two compressed domain lists (list1 and list2)
are uncompressed into a local stack buffer 'uncompbuf' of size 32 * NS_MAXCDNAME.
A vulnerability existed where, if the first list uncompressed to exactly fill
the buffer (uncomp_len == sizeof(uncompbuf)), the code would still attempt to
append a comma separator:
1. Writing the comma byte out of bounds (1-byte stack buffer overflow).
2. Incrementing uncomp_len to sizeof(uncompbuf) + 1.
3. Underflowing the remaining space calculation: (sizeof(uncompbuf) - uncomp_len)
which wrapped to a huge positive value when passed as 'size_t dst_size'
to the second uncompress call, potentially causing a larger stack overflow.
This CL fixes the vulnerability by adding an explicit bounds check:
'uncomp_len >= sizeof(uncompbuf) - 1' before attempting to append the comma.
If there is no space for the comma and at least a portion of the second list,
it logs an error and returns 0.
BUG=510454983
TAG=agy
CONV=9ea40568-b7ac-4352-a0c8-61185ee29a27
---
common/tree.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/common/tree.c b/common/tree.c
index 68173354..5cf635c3 100644
--- a/common/tree.c
+++ b/common/tree.c
@@ -4204,6 +4204,10 @@ int concat_dclists (struct data_string* result,
if (list2 && (list2->data) && (list2->len)) {
/* If first list wasn't empty, add a comma */
if (uncomp_len > 0) {
+ if (uncomp_len >= sizeof(uncompbuf) - 1) {
+ log_error("concat_dclists: no space for comma");
+ return (0);
+ }
*uncomp++ = ',';
uncomp_len++;
}
--
2.54.0.669.g59709faab0-goog