diff options
| author | Denys Fedoryshchenko <denys.f@collabora.com> | 2026-08-09 02:08:55 +0300 |
|---|---|---|
| committer | Vladislav Grishenko <themiron@users.noreply.github.com> | 2026-08-10 00:57:20 +0500 |
| commit | 1719b4ab756158f4a102bcf5036ff250d67ed015 (patch) | |
| tree | c976d51aff87a1910d931bbeed710a2f131343ce /accel-pppd/ctrl | |
| parent | 11271e9019ef1511b127b75e1c69e9c57f9cba49 (diff) | |
| download | accel-ppp-1719b4ab756158f4a102bcf5036ff250d67ed015.tar.gz accel-ppp-1719b4ab756158f4a102bcf5036ff250d67ed015.zip | |
sstp: reject packets shorter than header
A peer can send an SSTP packet with a zero encoded length and an unknown packet type. The receive dispatcher accepts the unknown type, after which buf_pull() consumes no data and the handler loops forever on the same packet, monopolizing a Triton worker.
Reject all packet lengths smaller than the SSTP header before dispatch so malformed packets close the connection without entering the non-progressing loop.
Diffstat (limited to 'accel-pppd/ctrl')
| -rw-r--r-- | accel-pppd/ctrl/sstp/sstp.c | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/accel-pppd/ctrl/sstp/sstp.c b/accel-pppd/ctrl/sstp/sstp.c index 61f4e163..2fd8cb35 100644 --- a/accel-pppd/ctrl/sstp/sstp.c +++ b/accel-pppd/ctrl/sstp/sstp.c @@ -2082,8 +2082,8 @@ static int sstp_handler(struct sstp_conn_t *conn, struct buffer_t *buf) } n = ntohs(hdr->length); - if (n > SSTP_MAX_PACKET_SIZE) { - log_ppp_error("recv [SSTP too long packet]\n"); + if (n < sizeof(*hdr) || n > SSTP_MAX_PACKET_SIZE) { + log_ppp_error("recv [SSTP invalid packet length %d]\n", n); return -1; } else if (n > buf->len) break; |
