mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-30 22:11:59 -09:00
Thanks to the OpenEmbedded community for the patches. This fixes the
following vulnerability:
- CVE-2026-29004:
BusyBox before commit 42202bf contains a heap buffer overflow
vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option
handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent
attackers to trigger memory corruption by sending a crafted DHCPv6
response with a malformed D6_OPT_DNS_SERVERS option. Attackers can
exploit incorrect heap buffer allocation calculations in the
option_to_env() function to cause denial of service or achieve
arbitrary code execution on embedded systems without heap hardening.
https://www.cve.org/CVERecord?id=CVE-2026-29004
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
(alternative to commit 5a27004cff)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
40 lines
1.2 KiB
Diff
40 lines
1.2 KiB
Diff
From d9a718cc17535c31d38f31fccb904a30e823166d Mon Sep 17 00:00:00 2001
|
|
From: Denys Vlasenko <vda.linux@googlemail.com>
|
|
Date: Thu, 12 Mar 2026 07:25:38 +0100
|
|
Subject: [PATCH] udhcpc6: fix buffer overflow
|
|
|
|
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
|
|
|
|
Upstream: https://github.com/vda-linux/busybox_mirror/commit/42202bfb1e6ac51fa995beda8be4d7b654aeee2a
|
|
CVE: CVE-2026-29004
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
networking/udhcp/d6_dhcpc.c | 6 +++---
|
|
1 file changed, 3 insertions(+), 3 deletions(-)
|
|
|
|
diff --git a/networking/udhcp/d6_dhcpc.c b/networking/udhcp/d6_dhcpc.c
|
|
index 79cef1999..d13b05829 100644
|
|
--- a/networking/udhcp/d6_dhcpc.c
|
|
+++ b/networking/udhcp/d6_dhcpc.c
|
|
@@ -351,15 +351,15 @@ static void option_to_env(const uint8_t *option, const uint8_t *option_end)
|
|
addrs = option[3] >> 4;
|
|
|
|
/* Setup environment variable */
|
|
- *new_env() = dlist = xmalloc(4 + addrs * 40 - 1);
|
|
+ *new_env() = dlist = xmalloc(4 + addrs * 40 + 1);
|
|
dlist = stpcpy(dlist, "dns=");
|
|
option_offset = 0;
|
|
|
|
- while (addrs--) {
|
|
+ while (addrs-- != 0) {
|
|
sprint_nip6(dlist, option + 4 + option_offset);
|
|
dlist += 39;
|
|
option_offset += 16;
|
|
- if (addrs)
|
|
+ if (addrs != 0)
|
|
*dlist++ = ' ';
|
|
}
|
|
|
|
--
|
|
2.34.1
|