Fix stack buffer overflow in packed_rr_to_string() - #5
Open
rtrappman-dev wants to merge 2 commits into
Open
rtrappman-dev wants to merge 2 commits into
rtrappman-dev wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix a bounds-checking defect in
packed_rr_to_string()that could write beyond its fixed 65,535-byte stack buffer.The function previously validated the assembled RR length only against
dest_len, which protects the caller's output buffer but does not necessarily protect the internalrr[65535]buffer.Some callers provide an output buffer larger than 65,535 bytes, allowing an oversized RR to pass the existing check and subsequently overflow
rr.Changes
dest_len, the caller-provided output buffer size.sizeof(rr), the fixed internal 65,535-byte assembly buffer.Security Impact
This closes a stack-based out-of-bounds write in the RR formatting path.
The affected condition is most relevant to callers that provide an output buffer larger than the internal
rrbuffer, including cache/control output paths.The fix converts the unsafe condition into a clean failure with the destination buffer cleared.
Testing
The regression test verifies that:
dest[0]is cleared on rejection.This change is based on the corresponding upstream Unbound security hardening fix.