Skip to content

bound literal copy in win32 cupsDNSSDAssembleFullName - #170

Closed
tanjiroK-coder wants to merge 1 commit into
OpenPrinting:masterfrom
tanjiroK-coder:dnssd-fullname-overflow
Closed

tanjiroK-coder wants to merge 1 commit into
OpenPrinting:masterfrom
tanjiroK-coder:dnssd-fullname-overflow

Conversation

@tanjiroK-coder

Copy link
Copy Markdown
Contributor

reading through the win32 branch of cupsDNSSDAssembleFullName in cups/dnssd.c i noticed the loop that copies the service instance name into the caller-provided fullname buffer only stops at the end of the source string. the branch that escapes spaces, backslashes and high-bit bytes checks (fullend - fullptr) < 4 before writing, but the plain literal-copy else branch does *fullptr++ = *name with no room check and the for itself carries no fullptr < fullend bound, so a name longer than fullsize walks off the end of the buffer. the helper takes fullsize precisely so it can keep its output inside the buffer, so this is the assembler overrunning the caller rather than caller misuse. the mDNSResponder and Avahi builds route through DNSServiceConstructFullName/avahi_service_name_join and are unaffected; only the hand-rolled Windows path is exposed. i added the same fullptr >= fullend guard the escape branch already uses so an over-long name fails cleanly instead of overwriting memory. checked with a small ASan harness over the extracted loop: a 500-byte name overruns a 64-byte buffer before the change and returns false after.

@michaelrsweet

Copy link
Copy Markdown
Member

OK, I changed things up and added more checks to let the caller know if the result didn't fit (previously it returned true if the name fix but didn't check the type or domain):

[master b0688d6] Fix a potential buffer overflow in cupsDNSSDAssembleFullName on Windows (Issue #170)

@michaelrsweet michaelrsweet self-assigned this Sep 29, 2026
@michaelrsweet michaelrsweet added bug Something isn't working platform issue Issue is specific to an OS or desktop labels Sep 29, 2026
@michaelrsweet michaelrsweet added this to the Stable milestone Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working platform issue Issue is specific to an OS or desktop

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants