summaryrefslogtreecommitdiff
path: root/MdePkg/Library/BaseMemoryLibRepStr/BaseMemoryLibRepStr.msa
diff options
context:
space:
mode:
authorjmestwa-coder <jmestwa@gmail.com>2026-05-26 14:36:27 +0300
committermergify[bot] <37929162+mergify[bot]@users.noreply.github.com>2026-09-29 03:34:21 +0300
commit4f9b239a60d51b89622b2a7ca9d5cbe3de86a4ad (patch)
tree522037ceb1a34baacfcafa57717a03bb78c2b5b4 /MdePkg/Library/BaseMemoryLibRepStr/BaseMemoryLibRepStr.msa
parentd07d3f5a5769cc8c9f76385174b73ea85525077d (diff)
downloadedk2-4f9b239a60d51b89622b2a7ca9d5cbe3de86a4ad.tar.xz
NetworkPkg/DnsDxe: Bound query name length in ParseDnsResponse
ParseDnsResponse() computes the query name length with AsciiStrLen on bytes taken straight from the received UDP datagram, before any bounds check. AsciiStrLen has no length cap in RELEASE builds, so a response whose question-name field carries no terminating zero makes the scan read past the end of the packet buffer returned by NetbufGetByte, an out-of-bounds read driven by attacker-controlled network input. Bound the scan with AsciiStrnLenS limited to RemainingLength, the bytes available from the name onward. The existing RemainingLength check then rejects a name that never terminates, which also makes the later AsciiStrLen(QueryName) uses provably in-bounds. Signed-off-by: Syed Mohammed Nayyar <jmestwa@gmail.com>
Diffstat (limited to 'MdePkg/Library/BaseMemoryLibRepStr/BaseMemoryLibRepStr.msa')
0 files changed, 0 insertions, 0 deletions