[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH 4/5] Avoid unbounded write in __PdoParseAddress



If a malicious backend sets the "mac" value longer than 6 pairs of
characters, not including the separator characters, it was possible
to write beyond the Address->Byte array.
Stop parsing the string if there are more than 6 hex pairs, and report
this as an invalid "mac" value.

Assisted-by: ClaudeCode:claude-opus-4.8
Signed-off-by: Owen Smith <owen.smith@xxxxxxxxxx>
---
 src/xenvif/pdo.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/src/xenvif/pdo.c b/src/xenvif/pdo.c
index 405506e..82b4de4 100644
--- a/src/xenvif/pdo.c
+++ b/src/xenvif/pdo.c
@@ -702,6 +702,10 @@ __PdoParseAddress(
         else
             break;
 
+        status = STATUS_INVALID_PARAMETER;
+        if (Length == ETHERNET_ADDRESS_LENGTH)
+            goto fail1;
+
         Address->Byte[Length++] = Byte;
 
         // Skip over any separator
@@ -711,10 +715,13 @@ __PdoParseAddress(
 
     status = STATUS_INVALID_PARAMETER;
     if (Length != ETHERNET_ADDRESS_LENGTH)
-        goto fail1;
+        goto fail2;
 
     return STATUS_SUCCESS;
 
+fail2:
+    Error("fail2\n");
+
 fail1:
     Error("fail1 (%08x)\n", status);
 
-- 
2.51.2.windows.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.