DragonFlyBSD Kernel Audit
← triage · dashboard
DF-2564

Decompress path signed integer underflow from missing minimum packet size check

Summary

ng_pred1_decompress checks only upper bound on packet size (:468 inlen>PRED1_BUF_SIZE) but no minimum. When compressed frame (cf bit set in 2-byte header) has fewer than 4 bytes total expression inlen-4 at :492 underflows to negative value passed as slen to Pred1Decompress. Pred1Decompress outer loop while(slen) treats negative slen as non-zero running unboundedly bounded only by dlen=4096 reading up to ~514 bytes past inbuf into outbuf within same heap allocation thoroughly corrupting prediction dictionary. Remote PPP peer sends 2-byte compressed frame [0x80 0x00]. Dictionary desync all subsequent frames fail CRC/length checks DoS.

Discussion (0)

No comments yet.