Skip to content

fix: prevent integer overflow in SocketMsghdr::packet_len() - #473

Open
a0xpg wants to merge 1 commit into
vivoblueos:mainfrom
a0xpg:fix/packet_len-integer-overflow
Open

a0xpg wants to merge 1 commit into
vivoblueos:mainfrom
a0xpg:fix/packet_len-integer-overflow

Conversation

@a0xpg

@a0xpg a0xpg commented Sep 13, 2026

Copy link
Copy Markdown

Replace Iterator::sum() with try_fold + checked_add to detect iovec length overflow. When an attacker sends a crafted iovec array via sendmsg() where the sum of iov_len exceeds usize::MAX, the wrapping addition previously caused packet_len to wrap to a small value. This would lead to an undersized heap buffer allocation and subsequent heap buffer overflow when gather_to_buffer() copies the actual data.

Fix: packet_len() now returns Option, returning None on overflow. The caller sendmsg() rejects the request with EINVAL when overflow is detected.

CWE-190: Integer Overflow -> CWE-122: Heap Buffer Overflow

Replace Iterator::sum() with try_fold + checked_add to detect iovec length overflow. When an attacker sends a crafted iovec array via sendmsg() where the sum of iov_len exceeds usize::MAX, the wrapping addition previously caused packet_len to wrap to a small value. This would lead to an undersized heap buffer allocation and subsequent heap buffer overflow when gather_to_buffer() copies the actual data.

Fix: packet_len() now returns Option<usize>, returning None on overflow. The caller sendmsg() rejects the request with EINVAL when overflow is detected.

CWE-190: Integer Overflow -> CWE-122: Heap Buffer Overflow
@CLAassistant

CLAassistant commented Sep 13, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants