dns/dnsmessage: add boundary check in unpackSVCBResource

Currently, bodyEnd is calculated using the length parameter from the
resource header without verifying if it exceeds the physical capacity
of the msg buffer.

If a malformed record provides a length that
exceeds the buffer, it bypasses the first-pass parameter validation
and causes an out-of-bounds slice during the second-pass copy.

Adding a check against len(msg) aligns this function with the boundary
enforcement used throughout the rest of the package.

Change-Id: I13f6ca83d1c30eac02286a49c12f8ec543d33e41
GitHub-Last-Rev: 78c35a160c45f09f2db04d9ec076dfb091a15595
GitHub-Pull-Request: golang/net#249
Reviewed-on: https://go-review.googlesource.com/c/net/+/781880
Reviewed-by: Sean Liao <sean@liao.dev>
Reviewed-by: ISMAIL GAMAL <ismailismailgamal52@gmail.com>
Reviewed-by: David Chase <drchase@google.com>
Reviewed-by: Junyang Shao <shaojunyang@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
2 files changed
tree: 7db0055707b17bc8de73cee2e56c6cf035729b90
  1. bpf/
  2. context/
  3. dict/
  4. dns/
  5. html/
  6. http/
  7. http2/
  8. http3/
  9. icmp/
  10. idna/
  11. internal/
  12. ipv4/
  13. ipv6/
  14. lif/
  15. nettest/
  16. netutil/
  17. proxy/
  18. publicsuffix/
  19. quic/
  20. route/
  21. trace/
  22. webdav/
  23. websocket/
  24. xsrftoken/
  25. .gitattributes
  26. .gitignore
  27. codereview.cfg
  28. CONTRIBUTING.md
  29. go.mod
  30. go.sum
  31. LICENSE
  32. PATENTS
  33. README.md
README.md

Go Networking

Go Reference

This repository holds supplementary Go networking packages.

Report Issues / Send Patches

This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.

The git repository is https://go.googlesource.com/net.

The main issue tracker for the net repository is located at https://go.dev/issues. Prefix your issue with “x/net:” in the subject line, so it is easy to find.