[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 4/5] Avoid unbounded write in __PdoParseAddress


  • To: Owen Smith <owen.smith@xxxxxxxxxx>, win-pv-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Tu Dinh <ngoc-tu.dinh@xxxxxxxxxx>
  • Date: Thu, 10 Sep 2026 15:38:16 +0200
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID"
  • Delivery-date: Thu, 10 Sep 2026 13:38:24 +0000
  • Feedback-id: default:8631fc262581453bbf619ec5b2062170:Sweego
  • List-id: Developer list for the Windows PV Drivers subproject <win-pv-devel.lists.xenproject.org>

On 10/09/2026 14:54, Owen Smith wrote:
> If a malicious backend sets the "mac" value longer than 6 pairs of
> characters, not including the separator characters, it was possible
> to write beyond the Address->Byte array.
> Stop parsing the string if there are more than 6 hex pairs, and report
> this as an invalid "mac" value.
> 
> Assisted-by: ClaudeCode:claude-opus-4.8
> Signed-off-by: Owen Smith <owen.smith@xxxxxxxxxx>

Reviewed-by: Tu Dinh <ngoc-tu.dinh@xxxxxxxxxx>

> ---
>   src/xenvif/pdo.c | 9 ++++++++-
>   1 file changed, 8 insertions(+), 1 deletion(-)
> 
> diff --git a/src/xenvif/pdo.c b/src/xenvif/pdo.c
> index 405506e..82b4de4 100644
> --- a/src/xenvif/pdo.c
> +++ b/src/xenvif/pdo.c
> @@ -702,6 +702,10 @@ __PdoParseAddress(
>           else
>               break;
>   
> +        status = STATUS_INVALID_PARAMETER;
> +        if (Length == ETHERNET_ADDRESS_LENGTH)
> +            goto fail1;
> +
>           Address->Byte[Length++] = Byte;
>   
>           // Skip over any separator
> @@ -711,10 +715,13 @@ __PdoParseAddress(
>   
>       status = STATUS_INVALID_PARAMETER;
>       if (Length != ETHERNET_ADDRESS_LENGTH)
> -        goto fail1;
> +        goto fail2;
>   
>       return STATUS_SUCCESS;
>   
> +fail2:
> +    Error("fail2\n");
> +
>   fail1:
>       Error("fail1 (%08x)\n", status);
>   



--
Ngoc Tu Dinh | Vates XCP-ng Developer

XCP-ng & Xen Orchestra - Vates solutions

web: https://vates.tech

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.