Summary: | buffer overrun in function make_request in sbin/dhclient/dhclient.c | ||||||
---|---|---|---|---|---|---|---|
Product: | Base System | Reporter: | Young <yangx92> | ||||
Component: | kern | Assignee: | freebsd-bugs (Nobody) <bugs> | ||||
Status: | Closed FIXED | ||||||
Severity: | Affects Many People | CC: | cem, dch, markj, splavecl | ||||
Priority: | --- | Keywords: | patch | ||||
Version: | CURRENT | ||||||
Hardware: | Any | ||||||
OS: | Any | ||||||
Attachments: |
|
Description
Young
2019-05-21 13:14:52 UTC
LGTM. cem@ seeing as you committed the last patch like this can you do it here, and MFC too? I put it in CURRENT but someone else can MFC if they like. A commit references this bug: Author: cem Date: Fri Nov 29 03:31:47 UTC 2019 New revision: 355204 URL: https://svnweb.freebsd.org/changeset/base/355204 Log: Fix braino in previous bugfix r300174 The previous revision missed the exact same error in a copy paste block of the same code in another function. Fix the identical case, too. A DHCP client identifier is simply the hardware type (one byte) concatenated with the hardware address (some variable number of bytes, but at most 16). Limit the size of the temporary buffer to match and the rest of the calculations shake out correctly. PR: 238022 Reported by: Young <yangx92 AT hotmail.com> Submitted by: Young <yangx92 AT hotmail.com> MFC after: I don't plan to but you should feel free Security: yes Changes: head/sbin/dhclient/dhclient.c A commit references this bug: Author: emaste Date: Sat Dec 7 03:56:37 UTC 2019 New revision: 355482 URL: https://svnweb.freebsd.org/changeset/base/355482 Log: MFC r238022 (cem): dhclient: fix braino in previous bugfix r300174 The previous revision missed the exact same error in a copy paste block of the same code in another function. Fix the identical case, too. A DHCP client identifier is simply the hardware type (one byte) concatenated with the hardware address (some variable number of bytes, but at most 16). Limit the size of the temporary buffer to match and the rest of the calculations shake out correctly. PR: 238022 Reported by: Young <yangx92 AT hotmail.com> Submitted by: Young <yangx92 AT hotmail.com> Changes: _U stable/12/ stable/12/sbin/dhclient/dhclient.c |