Project

General

Profile

Actions

Security #7464

closed
PA PA

doh2: buffer is not really limited to 65K as should be for DNS

Security #7464: doh2: buffer is not really limited to 65K as should be for DNS

Added by Philippe Antoine over 1 year ago. Updated 9 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
CVE:
Git IDs:
Severity:
MODERATE
Disclosure Date:
03/17/2025

Description

Found by oss-fuzz:
https://issues.oss-fuzz.com/u/1/issues/383880388

No need to backport as DOH2 is only in master

PA Updated by Philippe Antoine over 1 year ago Actions #1

  • Status changed from New to In Review

Gitlab MR

JI Updated by Jason Ish over 1 year ago Actions #3

Can we change the title? The current one seems ambiguous, perhaps:

doh2: enforce maximum buffer size of 65k

PA Updated by Philippe Antoine over 1 year ago Actions #4

Please do.

What was ambiguous ?

For information, there was a check for this 65K limit, but an incomplete one

JI Updated by Jason Ish over 1 year ago Actions #5

"not really limited".. Could be... Should be limited to 65k. Or should not be limited to 65k for whatever reason. So I'm not clear if the fix is enforce a 65k limit? Or something else.

PA Updated by Philippe Antoine over 1 year ago Actions #6

Jason Ish wrote in #note-5:

"not really limited".. Could be... Should be limited to 65k. Or should not be limited to 65k for whatever reason. So I'm not clear if the fix is enforce a 65k limit? Or something else.

The fix is indeed to really enforce the limit to 65K because the current enforcing does not work in all cases

PA Updated by Philippe Antoine over 1 year ago Actions #7

  • Status changed from In Review to Closed

JI Updated by Jason Ish 9 months ago Actions #8

  • Private changed from Yes to No
Actions

Also available in: PDF Atom