Repository navigation
[components][lwip] DHCP 服务器解析选项时检查缓冲区边界 - #11858
cms19859230182-lang wants to merge 2 commits into
Conversation
|
👋 感谢您对 RT-Thread 的贡献!Thank you for your contribution to RT-Thread! 为确保代码符合 RT-Thread 的编码规范,请在你的仓库中执行以下步骤运行代码格式化工作流(如果格式化CI运行失败)。 🛠 操作步骤 | Steps
完成后,提交将自动更新至 如有问题欢迎联系我们,再次感谢您的贡献!💐 |
📌 Code Review Assignment🏷️ Tag: componentsReviewers: @Maihuanyi Changed Files (Click to expand)
📊 Current Review Status (Last Updated: 2026-10-09 11:18 CST)
📝 Review Instructions
|
|
建议拆成两笔 commit,方便审核和合并,分别是改动主体和格式化 |
|
好的 |
The option loop advanced by the option length without checking the number of bytes actually received by recvfrom(), so a malformed or truncated DHCP packet could make the server read past the end of the receive buffer. Check that the option type, length and payload stay inside the received data before reading them, and stop parsing when a requested IP option is shorter than 4 bytes or a message type option is shorter than 1 byte. Fixes RT-Thread#11323
4f77231 to
752bd6b
Compare
拉取/合并请求描述:(PR description)
[
为什么提交这份PR (why to submit this PR)
Fixes #11323
components/net/lwip-dhcpd/dhcp_server.c解析 DHCP 选项时,while (finished == 0)按选项长度往前走,不看recvfrom实际收到的字节数。畸形包会越界读。你的解决方案是什么 (what is your solution)
用
bytes_read作为缓冲区末尾。读选项类型和长度之前至少要剩下 2 字节;选项内容也必须落在已收到的字节里,不够就停。请求 IP 的长度不足 4、消息类型的长度不足 1 时,不再按固定偏移去读。长度合法的包,解析结果和原来一样。END(0xFF)按协议只有 1 字节,没有长度字段。原代码会读它后面的那一字节当长度。这次在后面没有字节时直接停,不再越界;已经解析到的字段保留。改动按审核建议拆成两笔提交:
[components][lwip] dhcpd: check buffer bounds when parsing options:只包含上面的边界检查。[components][lwip] dhcpd: apply clang-format to dhcp_server.c:只用仓库根目录的.clang-format(clang-format 19.1.7)格式化整个文件。除了给 4 处单语句补上大括号,不改变任何逻辑。请提供验证的bsp和config (provide the config and bsp)
LWIP_USING_DHCPD]
当前拉取/合并请求的状态 Intent for your PR
必须选择一项 Choose one (Mandatory):
代码质量 Code Quality:
我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:
#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up