|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH 4/5] Avoid unbounded write in __PdoParseAddress
On 10/09/2026 14:54, Owen Smith wrote:
> If a malicious backend sets the "mac" value longer than 6 pairs of
> characters, not including the separator characters, it was possible
> to write beyond the Address->Byte array.
> Stop parsing the string if there are more than 6 hex pairs, and report
> this as an invalid "mac" value.
>
> Assisted-by: ClaudeCode:claude-opus-4.8
> Signed-off-by: Owen Smith <owen.smith@xxxxxxxxxx>
Reviewed-by: Tu Dinh <ngoc-tu.dinh@xxxxxxxxxx>
> ---
> src/xenvif/pdo.c | 9 ++++++++-
> 1 file changed, 8 insertions(+), 1 deletion(-)
>
> diff --git a/src/xenvif/pdo.c b/src/xenvif/pdo.c
> index 405506e..82b4de4 100644
> --- a/src/xenvif/pdo.c
> +++ b/src/xenvif/pdo.c
> @@ -702,6 +702,10 @@ __PdoParseAddress(
> else
> break;
>
> + status = STATUS_INVALID_PARAMETER;
> + if (Length == ETHERNET_ADDRESS_LENGTH)
> + goto fail1;
> +
> Address->Byte[Length++] = Byte;
>
> // Skip over any separator
> @@ -711,10 +715,13 @@ __PdoParseAddress(
>
> status = STATUS_INVALID_PARAMETER;
> if (Length != ETHERNET_ADDRESS_LENGTH)
> - goto fail1;
> + goto fail2;
>
> return STATUS_SUCCESS;
>
> +fail2:
> + Error("fail2\n");
> +
> fail1:
> Error("fail1 (%08x)\n", status);
>
--
Ngoc Tu Dinh | Vates XCP-ng Developer
XCP-ng & Xen Orchestra - Vates solutions
web: https://vates.tech
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |