aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKen Chen <cken@google.com>2020-08-30 05:25:44 +0000
committerAutomerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>2020-08-30 05:25:44 +0000
commitcf6b3ecd4d9036e8b84489549441c86d1576a796 (patch)
tree3b2683ba5691ba3c45cb2e12421650638f0584f9
parentd43f9a88313418f7e786a6151a4ef966ce5a61ce (diff)
parent2c2546b158ec41ea68fda23c884c04b13f98ce44 (diff)
downloadbionic-cf6b3ecd4d9036e8b84489549441c86d1576a796.tar.gz
Fix OOB read in DNS resolver am: 43264bc365 am: c5ea7569a8 am: 2c2546b158
Original change: https://googleplex-android-review.googlesource.com/c/platform/bionic/+/12329970 Change-Id: I5e167b6717d7f90ba782e26ef553fb6d302b493a
-rw-r--r--libc/dns/resolv/res_send.c4
1 files changed, 3 insertions, 1 deletions
diff --git a/libc/dns/resolv/res_send.c b/libc/dns/resolv/res_send.c
index a645a6b4a..fa81e6dc5 100644
--- a/libc/dns/resolv/res_send.c
+++ b/libc/dns/resolv/res_send.c
@@ -948,6 +948,8 @@ send_vc(res_state statp, struct __res_params* params,
else
break;
}
+ // return size should never exceed container size
+ resplen = anssiz;
}
/*
* If the calling applicating has bailed out of
@@ -960,7 +962,7 @@ send_vc(res_state statp, struct __res_params* params,
DprintQ((statp->options & RES_DEBUG) ||
(statp->pfcode & RES_PRF_REPLY),
(stdout, ";; old answer (unexpected):\n"),
- ans, (resplen > anssiz) ? anssiz: resplen);
+ ans, resplen);
goto read_len;
}