DHCP server unbounded option parsing - OOB read from packet buffer
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Tranquilo
- Stack tecnológico
- c
- Área
- embedded-iot, networking, security
Línea de trabajo
Empieza en components/net/lwip-dhcpd/dhcp_server.c, en la línea 346, y sigue cómo se representan la longitud del paquete recibido y la posición de la opción. Compila el servidor DHCP con AddressSanitizer y envía el paquete DHCP malformado descrito, incluidos los marcadores de fin ausentes y las longitudes de opción excesivas. El trabajo está terminado cuando las opciones malformadas ya no provocan lecturas más allá del búfer del paquete.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
RT-Thread Version
tested HEAD, commit 38c007af
Hardware Type/Architectures
independent (Bug is in lwip-dhcpd C implementation)
Develop Toolchain
Other
Describe the bug
Summary
A buffer over-read vulnerability exists in RT-Thread's DHCP server implementation (components/net/lwip-dhcpd/dhcp_server.c) where the DHCP option parsing loop has no bounds check on the input buffer position, allowing a crafted DHCP packet to read past the allocated buffer.
Details
File: components/net/lwip-dhcpd/dhcp_server.c, line 346
The DHCP options parsing loop uses while(finished == 0) to iterate through options in the received packet. The loop reads option type and length fields from the packet data but does NOT check whether the current read position exceeds the packet buffer boundary.
/* dhcp_server.c:346 */
while(finished == 0) {
/* reads option type and length from packet data */
/* NO check that position < packet_length */
}
Since DHCP packets are received over the network with no authentication, this is reachable pre-authentication on the local network segment.
PoC
Send a crafted DHCP packet on the local network segment with:
- Valid DHCP header (op=1, htype=1, hlen=6)
- Options section containing a chain of options where each option's length field points past the end of the packet
- No DHCP_OPTION_END (0xFF) marker
The server's option parsing loop will read past the packet buffer boundary until it hits unmapped memory (crash) or reads adjacent heap data (info leak).
Build and run the RT-Thread DHCP server component with AddressSanitizer enabled to observe the over-read:
# Cross-compile RT-Thread with ASAN, enable lwip-dhcpd,
# send crafted DHCP DISCOVER on the local interface
Other additional context
Impact
- Out-of-bounds read from the packet buffer
- Potential information disclosure from adjacent heap memory
- Potential crash (DoS) if reading into unmapped memory
- Affects any RT-Thread device running the built-in DHCP server
- Attack vector: adjacent network (DHCP is link-local), no authentication required
Suggested fix:
- while(finished == 0) {
+ while(finished == 0 && position < packet_length) {
Also validate that position + option_length does not exceed packet_length before reading option data.
- Lenguaje dominante
- C
- Estrellas
- 12.3k
- Forks
- 5.5k
- Merge medio
- 4 d 12 h
- PR fusionados (30 d)
- 32
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de RT-Thread/rt-thread
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
RT-Thread/rt-thread#11818 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
BSP BSP: Loongson bug RT-Smart
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RT-Thread/rt-thread#11717 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Arch: RISC-V BSP BSP: HPMicro bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RT-Thread/rt-thread#11687 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
RT-Thread/rt-thread#11472 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized InputPosiblemente ocupada @Acen28 la tomó hace 7 días. AbiertoArch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread/rt-thread#11839 · 3 comentarios · 1 asignado ·
Los mantenedores suelen responder en 1 día
Todos los issues de RT-Thread/rt-thread
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
E editing with a field wider than ~511 characters crashes (stack smashing in handle_decimal)Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 2 días
-
Additional warning optionsAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
-
Missing zeroAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
projecthorus/radiosonde_auto_rx#1116 · 1 comentario ·