mirror of
http://thekelleys.org.uk/git/dnsmasq.git
synced 2026-10-07 15:44:08 +07:00
Thanks to Michalis Vasileiadis for spotting this. print_mac() writes each MAC byte to its output buffer with unbounded sprintf and is called from main() with pkt.header.hlen straight out of a BOOTREPLY. hlen is an attacker-controlled uint8_t (up to 255), each byte expands to up to 3 chars, and the destination is a 500-byte stack buffer. A malicious leasequery server that echoes the client's transaction ID and replies with DHCPLEASEACTIVE and an oversized hlen overflows that stack buffer. The patch caps len inside print_mac at DHCP_CHADDR_MAX (16), which is the actual size of chaddr in the BOOTP header and an upper bound on any legitimate hardware-address length. The other in-file caller of print_mac already clamps its length argument to 14 before the call, so this change is local to the vulnerable path.