Branch: refs/heads/master
Home: https://github.com/tianocore/edk2
Commit: 9bf69ed7ed03d88535a43987e5b8105406b42d57
https://github.com/tianocore/edk2/commit/9bf69ed7ed03d88535a43987e5b8105406b42d57
Author: jmestwa-coder <[email protected]>
Date: 2026-06-18 (Thu, 18 Jun 2026)
Changed paths:
M NetworkPkg/Dhcp6Dxe/Dhcp6Impl.h
M NetworkPkg/Dhcp6Dxe/Dhcp6Io.c
M NetworkPkg/Dhcp6Dxe/GoogleTest/Dhcp6IoGoogleTest.cpp
Log Message:
-----------
NetworkPkg/Dhcp6Dxe: bound IA inner option length to buffer
Dhcp6SeekInnerOptionSafe() reads the IA_NA/IA_TA option-len field from a
received datagram and only validates it against the fixed minimums, never
against OptionLen (the bytes actually remaining in the packet). A reply
can declare an option-len up to 0xFFFF while the real buffer is only the
16-byte (IA_NA) or 8-byte (IA_TA) minimum, so the returned inner length
is far larger than the buffer.
That length is then passed as SeekLen to Dhcp6SeekOption(), which walks
ReadUnaligned16() cursors up to Buf + SeekLen and reads past the end of
the packet allocation, an attacker-controlled out-of-bounds read.
Bound the declared inner length against OptionLen minus the IA header
size in both the IA_NA and IA_TA branches, rejecting over-declared
options with EFI_DEVICE_ERROR. Parenthesize DHCP6_MIN_SIZE_OF_IA_NA so
the subtraction in that bound binds correctly. Add host tests covering
the over-declared, off-by-one, and exact-boundary cases for both IA_NA
and IA_TA.
Signed-off-by: jmestwa-coder <[email protected]>
To unsubscribe from these emails, change your notification settings at
https://github.com/tianocore/edk2/settings/notifications
_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits