dns/dnsmessage: add boundary check in unpackSVCBResource Currently, bodyEnd is calculated using the length parameter from the resource header without verifying if it exceeds the physical capacity of the msg buffer. If a malformed record provides a length that exceeds the buffer, it bypasses the first-pass parameter validation and causes an out-of-bounds slice during the second-pass copy. Adding a check against len(msg) aligns this function with the boundary enforcement used throughout the rest of the package. Change-Id: I13f6ca83d1c30eac02286a49c12f8ec543d33e41 GitHub-Last-Rev: 78c35a160c45f09f2db04d9ec076dfb091a15595 GitHub-Pull-Request: golang/net#249 Reviewed-on: https://go-review.googlesource.com/c/net/+/781880 Reviewed-by: Sean Liao <sean@liao.dev> Reviewed-by: ISMAIL GAMAL <ismailismailgamal52@gmail.com> Reviewed-by: David Chase <drchase@google.com> Reviewed-by: Junyang Shao <shaojunyang@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
This repository holds supplementary Go networking packages.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.
The git repository is https://go.googlesource.com/net.
The main issue tracker for the net repository is located at https://go.dev/issues. Prefix your issue with “x/net:” in the subject line, so it is easy to find.