|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH 4/5] Avoid unbounded write in __PdoParseAddress
If a malicious backend sets the "mac" value longer than 6 pairs of
characters, not including the separator characters, it was possible
to write beyond the Address->Byte array.
Stop parsing the string if there are more than 6 hex pairs, and report
this as an invalid "mac" value.
Assisted-by: ClaudeCode:claude-opus-4.8
Signed-off-by: Owen Smith <owen.smith@xxxxxxxxxx>
---
src/xenvif/pdo.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/src/xenvif/pdo.c b/src/xenvif/pdo.c
index 405506e..82b4de4 100644
--- a/src/xenvif/pdo.c
+++ b/src/xenvif/pdo.c
@@ -702,6 +702,10 @@ __PdoParseAddress(
else
break;
+ status = STATUS_INVALID_PARAMETER;
+ if (Length == ETHERNET_ADDRESS_LENGTH)
+ goto fail1;
+
Address->Byte[Length++] = Byte;
// Skip over any separator
@@ -711,10 +715,13 @@ __PdoParseAddress(
status = STATUS_INVALID_PARAMETER;
if (Length != ETHERNET_ADDRESS_LENGTH)
- goto fail1;
+ goto fail2;
return STATUS_SUCCESS;
+fail2:
+ Error("fail2\n");
+
fail1:
Error("fail1 (%08x)\n", status);
--
2.51.2.windows.1
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |