The DHCPv6 client takes the SERVERID and CLIENTID option lengths from a
received ADVERTISE/REPLY without bounding them. The SERVERID length is
later copied unbounded into the fixed net_tx_packet buffer when the
REQUEST is built (an out-of-bounds write), and the CLIENTID length
drives a memcmp against the fixed client-DUID buffer (an out-of-bounds
read).
Both are reachable by any on-link attacker that answers a DHCPv6 SOLICIT
during netboot.

Patch 1 bounds both lengths at parse time. Patch 2 adds sandbox DM
regression tests that inject an ADVERTISE with an over-long SERVERID or
CLIENTID and check the client rejects it.

Based on master (baa64b2f892). A reproducer is available on request.

Signed-off-by: Shahriyar Jalayeri <[email protected]>
---
Shahriyar Jalayeri (2):
      net: dhcp6: bound received DUID option lengths
      test: dm: eth: add DHCPv6 oversized option regression tests

 net/dhcpv6.c  |  12 +++--
 net/dhcpv6.h  |   3 ++
 test/dm/eth.c | 151 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 3 files changed, 162 insertions(+), 4 deletions(-)
---
base-commit: baa64b2f892890f00a377eac4a3e685472bb56b5
change-id: 20260806-b4-dhcp6-serverid-oob-06d0eb283aac

Best regards,
--  
Shahriyar Jalayeri <[email protected]>

Reply via email to