Skip to content

Fix DNS name encode/decode buffer overflows (#851)#854

Open
LL-V wants to merge 1 commit into
ithewei:masterfrom
LL-V:fix/dns-name-bounds
Open

Fix DNS name encode/decode buffer overflows (#851)#854
LL-V wants to merge 1 commit into
ithewei:masterfrom
LL-V:fix/dns-name-bounds

Conversation

@LL-V

@LL-V LL-V commented Jul 23, 2026

Copy link
Copy Markdown

Summary

Fixes #851.

Bound DNS name encode/decode to DNS_NAME_MAXLEN, reject overlong labels, NUL-terminate name on compression pointers, fail pack on encode error.

Test plan

dns_name_decode and dns_name_encode did not enforce DNS_NAME_MAXLEN or
label length limits, allowing OOB writes into dns_rr_t.name and the
encode stack buffer. Compression-pointer RRs also left name[]
uninitialized.

Add bounds checks, reject overlong labels, NUL-terminate name on
compression pointers, and fail encode/pack on overflow (see ithewei#851).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses the memory-safety issues reported in #851 by adding stricter bounds/validation to DNS name encoding/decoding and by ensuring dns_rr_unpack does not leave rr->name uninitialized when encountering compression pointers.

Changes:

  • Add DNS label length validation (<= 63) and cap encode/decode operations to DNS_NAME_MAXLEN.
  • Make dns_rr_pack fail fast when name encoding fails, and size the encoded-name buffer using DNS_NAME_MAXLEN.
  • Ensure dns_rr_unpack NUL-terminates rr->name for compression-pointer names and adds additional length checks.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread protocol/dns.c
Comment on lines +45 to +48
*plen = (char)len;
if (buf >= end) return -1;
*buf++ = '\0';
return (int)(buf - start);
Comment thread protocol/dns.c
Comment on lines 143 to +147
else {
namelen = dns_name_decode(buf, rr->name);
}
if (namelen < 0) return -1;
if (namelen > len) return -1;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: OOB write/read in protocol/dns.c dns_name_decode/encode and compression path

2 participants