summaryrefslogtreecommitdiff
path: root/accel-pppd/ctrl
diff options
context:
space:
mode:
authorDenys Fedoryshchenko <denys.f@collabora.com>2026-08-09 02:08:55 +0300
committerVladislav Grishenko <themiron@users.noreply.github.com>2026-08-10 00:57:20 +0500
commit1719b4ab756158f4a102bcf5036ff250d67ed015 (patch)
treec976d51aff87a1910d931bbeed710a2f131343ce /accel-pppd/ctrl
parent11271e9019ef1511b127b75e1c69e9c57f9cba49 (diff)
downloadaccel-ppp-1719b4ab756158f4a102bcf5036ff250d67ed015.tar.gz
accel-ppp-1719b4ab756158f4a102bcf5036ff250d67ed015.zip
sstp: reject packets shorter than header
A peer can send an SSTP packet with a zero encoded length and an unknown packet type. The receive dispatcher accepts the unknown type, after which buf_pull() consumes no data and the handler loops forever on the same packet, monopolizing a Triton worker. Reject all packet lengths smaller than the SSTP header before dispatch so malformed packets close the connection without entering the non-progressing loop.
Diffstat (limited to 'accel-pppd/ctrl')
-rw-r--r--accel-pppd/ctrl/sstp/sstp.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/accel-pppd/ctrl/sstp/sstp.c b/accel-pppd/ctrl/sstp/sstp.c
index 61f4e163..2fd8cb35 100644
--- a/accel-pppd/ctrl/sstp/sstp.c
+++ b/accel-pppd/ctrl/sstp/sstp.c
@@ -2082,8 +2082,8 @@ static int sstp_handler(struct sstp_conn_t *conn, struct buffer_t *buf)
}
n = ntohs(hdr->length);
- if (n > SSTP_MAX_PACKET_SIZE) {
- log_ppp_error("recv [SSTP too long packet]\n");
+ if (n < sizeof(*hdr) || n > SSTP_MAX_PACKET_SIZE) {
+ log_ppp_error("recv [SSTP invalid packet length %d]\n", n);
return -1;
} else if (n > buf->len)
break;