From: Sriram Sriram <sriramsriram@linux.microsoft.com>
To: u-boot@lists.u-boot-project.org
Cc: Tom Rini <trini@konsulko.com>,
Jerome Forissier <jerome.forissier@arm.com>,
Drew Kluemke <ankluemk@microsoft.com>,
Daniel Munic <v-dmunic@microsoft.com>,
Sriram Sriram <sriramsriram@linux.microsoft.com>
Subject: [PATCH v2 2/3] net: tftp: verify the OACK packet is NUL terminated
Date: Tue, 15 Sep 2026 13:52:09 -0700 [thread overview]
Message-ID: <20260915205210.260404-3-sriramsriram@linux.microsoft.com> (raw)
In-Reply-To: <20260915205210.260404-1-sriramsriram@linux.microsoft.com>
From: Drew Kluemke <ankluemk@microsoft.com>
The OACK handler matches option names with strcasecmp() and parses the
values with dectoul(). Both scan until a NUL byte, so a malformed or
truncated OACK that contains no NUL within the received length makes
them read past the end of the packet buffer.
RFC 2347 formats an OACK as a sequence of NUL terminated netascii
strings, so the last byte of a well-formed packet is always a NUL.
Check for it once on entry and drop the packet if it is missing, which
keeps every strcasecmp() and dectoul() below in bounds without having to
bound each one individually.
Signed-off-by: Drew Kluemke <ankluemk@microsoft.com>
Signed-off-by: Sriram Sriram <sriramsriram@linux.microsoft.com>
---
Changes in v2:
- Replaced the four bounded strncasecmp() comparisons with a single
check that the packet ends in a NUL, per Tom's review. RFC 2347
guarantees the trailing NUL, so one test covers every strcasecmp()
and, unlike v1, the dectoul() calls as well.
- Smaller: +16 bytes of .text on am335x_evm_defconfig, against +24 for
v1 (net/tftp.o 3222 unpatched, 3246 in v1, 3238 here).
- Retitled from "net: tftp: use bounded string compare for OACK option
parsing" to match the new approach.
net/tftp.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/tftp.c b/net/tftp.c
index beb9d08f5a2..73b31b8357d 100644
--- a/net/tftp.c
+++ b/net/tftp.c
@@ -528,6 +528,13 @@ static void tftp_handler(uchar *pkt, unsigned dest, struct in_addr sip,
#endif
case TFTP_OACK:
+ /*
+ * RFC 2347 makes every option name and value a NUL terminated
+ * string, so a well-formed OACK always ends in a NUL. Checking
+ * that once keeps the option parsing below in bounds.
+ */
+ if (!len || pkt[len - 1] != '\0')
+ return;
debug("Got OACK: ");
for (i = 0; i < len; i++) {
if (pkt[i] == '\0')
--
2.49.0
next prev parent reply other threads:[~2026-09-15 20:52 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 19:20 [PATCH 0/4] Bounds/overflow hardening in NFS, FIT, TFTP and ext4 Sriram Sriram
2026-09-09 19:20 ` [PATCH 1/4] net: nfs: add bounds checks on memcpy into stack-allocated rpc_pkt Sriram Sriram
2026-09-09 19:20 ` [PATCH 2/4] boot: image-fit: add overflow guard for FIT decompression buffer Sriram Sriram
2026-09-10 19:09 ` Tom Rini
2026-09-09 19:20 ` [PATCH 3/4] net: tftp: use bounded string compare for OACK option parsing Sriram Sriram
2026-09-10 19:25 ` Tom Rini
2026-09-09 19:20 ` [PATCH 4/4] fs: ext4: widen ext4fs_update() block-group loop counter Sriram Sriram
2026-09-15 20:52 ` [PATCH v2 0/3] Bounds hardening in NFS, TFTP and ext4 Sriram Sriram
2026-09-15 20:52 ` [PATCH v2 1/3] net: nfs: add bounds checks on memcpy into stack-allocated rpc_pkt Sriram Sriram
2026-09-17 9:03 ` Jerome Forissier
2026-09-15 20:52 ` Sriram Sriram [this message]
2026-09-17 8:51 ` [PATCH v2 2/3] net: tftp: verify the OACK packet is NUL terminated Jerome Forissier
2026-09-15 20:52 ` [PATCH v2 3/3] fs: ext4: widen ext4fs_update() block-group loop counter Sriram Sriram
2026-09-15 21:23 ` Tony Dinh
2026-10-01 1:20 ` (subset) [PATCH v2 0/3] Bounds hardening in NFS, TFTP and ext4 Tom Rini
2026-10-01 15:47 ` Sriram Sriram
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915205210.260404-3-sriramsriram@linux.microsoft.com \
--to=sriramsriram@linux.microsoft.com \
--cc=ankluemk@microsoft.com \
--cc=jerome.forissier@arm.com \
--cc=trini@konsulko.com \
--cc=u-boot@lists.u-boot-project.org \
--cc=v-dmunic@microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).