diff options
author | Ken Chen <cken@google.com> | 2020-08-30 04:49:07 +0000 |
---|---|---|
committer | Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com> | 2020-08-30 04:49:07 +0000 |
commit | c5ea7569a80468665fd80ff3f987dd5ca5d2e7e1 (patch) | |
tree | c31ce4ca29f9f36eacbd4f1ec8a8cc088d038c2a | |
parent | 5cda74e065761bbeccf7ff61d7a3131bdf6490d0 (diff) | |
parent | 43264bc36557db9a281b321aab16e574401dfddc (diff) | |
download | bionic-c5ea7569a80468665fd80ff3f987dd5ca5d2e7e1.tar.gz |
Fix OOB read in DNS resolver am: 43264bc365
Original change: https://googleplex-android-review.googlesource.com/c/platform/bionic/+/12329970
Change-Id: Ief989a779e7fea19a92fb90a863017ecdb1bc7a3
-rw-r--r-- | libc/dns/resolv/res_send.c | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/libc/dns/resolv/res_send.c b/libc/dns/resolv/res_send.c index a645a6b4a..fa81e6dc5 100644 --- a/libc/dns/resolv/res_send.c +++ b/libc/dns/resolv/res_send.c @@ -948,6 +948,8 @@ send_vc(res_state statp, struct __res_params* params, else break; } + // return size should never exceed container size + resplen = anssiz; } /* * If the calling applicating has bailed out of @@ -960,7 +962,7 @@ send_vc(res_state statp, struct __res_params* params, DprintQ((statp->options & RES_DEBUG) || (statp->pfcode & RES_PRF_REPLY), (stdout, ";; old answer (unexpected):\n"), - ans, (resplen > anssiz) ? anssiz: resplen); + ans, resplen); goto read_len; } |