Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

DHCP server unbounded option parsing - OOB read from packet buffer

オープン
#11,323 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
c

調査の方向性

components/net/lwip-dhcpd/dhcp_server.c の 346 行目から始め、受信パケットの長さとオプションの位置がどのように表現されているかを追跡します。AddressSanitizer を有効にして DHCP サーバーをビルドし、終端マーカーの欠落やオプション長の過大な値を含む、説明された不正な DHCP パケットを送信します。不正なオプションによってパケットバッファーの範囲外の読み取りが発生しなくなれば完了です。

索引モデルが issue の本文から書いたものです。

説明

RT-Thread Version

tested HEAD, commit 38c007af

Hardware Type/Architectures

independent (Bug is in lwip-dhcpd C implementation)

Develop Toolchain

Other

Describe the bug
Summary

A buffer over-read vulnerability exists in RT-Thread's DHCP server implementation (components/net/lwip-dhcpd/dhcp_server.c) where the DHCP option parsing loop has no bounds check on the input buffer position, allowing a crafted DHCP packet to read past the allocated buffer.

Details

File: components/net/lwip-dhcpd/dhcp_server.c, line 346

The DHCP options parsing loop uses while(finished == 0) to iterate through options in the received packet. The loop reads option type and length fields from the packet data but does NOT check whether the current read position exceeds the packet buffer boundary.

/* dhcp_server.c:346 */
while(finished == 0) {
    /* reads option type and length from packet data */
    /* NO check that position < packet_length */
}

Since DHCP packets are received over the network with no authentication, this is reachable pre-authentication on the local network segment.

PoC

Send a crafted DHCP packet on the local network segment with:

  • Valid DHCP header (op=1, htype=1, hlen=6)
  • Options section containing a chain of options where each option's length field points past the end of the packet
  • No DHCP_OPTION_END (0xFF) marker

The server's option parsing loop will read past the packet buffer boundary until it hits unmapped memory (crash) or reads adjacent heap data (info leak).

Build and run the RT-Thread DHCP server component with AddressSanitizer enabled to observe the over-read:

# Cross-compile RT-Thread with ASAN, enable lwip-dhcpd,
# send crafted DHCP DISCOVER on the local interface
Other additional context
Impact
  • Out-of-bounds read from the packet buffer
  • Potential information disclosure from adjacent heap memory
  • Potential crash (DoS) if reading into unmapped memory
  • Affects any RT-Thread device running the built-in DHCP server
  • Attack vector: adjacent network (DHCP is link-local), no authentication required

Suggested fix:

- while(finished == 0) {
+ while(finished == 0 && position < packet_length) {

Also validate that position + option_length does not exceed packet_length before reading option data.

主要言語
C
スター
12.3k
フォーク
5.5k
平均マージ
4日 12時間
マージ済み PR(30日)
32

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

RT-Thread/rt-thread のほかの issue

RT-Thread/rt-thread の issue をすべて見る

似ている issue

C の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。