Skip to content

Validate PicoTCP DNS responses - #2416

Open
acts-1631 wants to merge 4 commits into
flyinghead:masterfrom
acts-1631:security-fix-picotcp-dns-responses
Open

Validate PicoTCP DNS responses#2416
acts-1631 wants to merge 4 commits into
flyinghead:masterfrom
acts-1631:security-fix-picotcp-dns-responses

Conversation

@acts-1631

Copy link
Copy Markdown
Contributor

PicoTCP accepted the first UDP response received during startup DNS
resolution and parsed DNS names and record lengths without validating
the received length. A forged or malformed response could read past
Flycast's resolver buffer and terminate the process.

This matches replies to the queried endpoint and transaction ID, and
performs bounds checks for DNS questions, names, records, and record
data before reading them.

CUE and GDI descriptor parsing continued appending after a quoted
filename reached end of input. A malformed descriptor could consume
CPU and memory until Flycast stopped responding.

Treat failed character extraction as an invalid descriptor while
skipping whitespace and while scanning quoted filenames.
The ISO9660 reader constructed filenames using record lengths supplied
by the disc without confirming that the record remained in the loaded
directory buffer. A malformed image could read past that buffer.

Reject incomplete records and filenames before accessing their fields.
RZIP savestate headers controlled allocation sizes without a limit or
an allocation failure boundary. A malicious savestate could terminate
Flycast by requesting an impractically large allocation.

Reject oversized chunks and handle allocation failures when reading
compressed chunk data.
The PicoTCP DNS resolver accepted the first UDP response and parsed
DNS fields without checking the received length. A malformed response
could read past the resolver buffer and terminate Flycast.

Match replies to the queried endpoint and transaction ID, then validate
DNS names, records, and data lengths before reading them.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant