Skip to content

Fix stack buffer overflow in packed_rr_to_string() - #5

Open
rtrappman-dev wants to merge 2 commits into
firewalla:v1.25from
rtrappman-dev:fix/packed_rr_to_string()
Open

rtrappman-dev wants to merge 2 commits into
firewalla:v1.25from
rtrappman-dev:fix/packed_rr_to_string()

Conversation

@rtrappman-dev

Copy link
Copy Markdown

Summary

Fix a bounds-checking defect in packed_rr_to_string() that could write beyond its fixed 65,535-byte stack buffer.

The function previously validated the assembled RR length only against dest_len, which protects the caller's output buffer but does not necessarily protect the internal rr[65535] buffer.

Some callers provide an output buffer larger than 65,535 bytes, allowing an oversized RR to pass the existing check and subsequently overflow rr.

Changes

  • Validate the assembled RR length against both:
    • dest_len, the caller-provided output buffer size.
    • sizeof(rr), the fixed internal 65,535-byte assembly buffer.
  • Add regression coverage for:
    • An RR that exactly fills the 65,535-byte internal buffer.
    • An RR that exceeds the internal buffer by one byte.
    • An oversized RDATA value that causes the assembled RR to exceed 65,535 bytes.

Security Impact

This closes a stack-based out-of-bounds write in the RR formatting path.

The affected condition is most relevant to callers that provide an output buffer larger than the internal rr buffer, including cache/control output paths.

The fix converts the unsafe condition into a clean failure with the destination buffer cleared.

Testing

The regression test verifies that:

  • Maximum-size input accepted by the internal buffer continues to succeed.
  • Input exceeding the internal buffer is rejected.
  • dest[0] is cleared on rejection.

This change is based on the corresponding upstream Unbound security hardening fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant