HomeDefectsLIN1024-5820
Fixed

LIN1024-5820 : kea: fail to handle empty DHCPDISCOVER packet

Created: Dec 17, 2024    Updated: Jan 20, 2025
Resolved Date: Jan 9, 2025
Found In Version: 10.24.33.3
Fix Version: 10.24.33.5
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

If the reveived DHCPDISCOVER packet doesn't hold any DHCP data, the length and position of the buffer end up being the same.

This leads to readVector failing to read the zero extra bytes when accessing data[0], causing the kea process to crash:
    
kea-dhcp4[596]: /usr/include/c++/13.3.0/bits/stl_vector.h:1128: std::vector<Tp, _Alloc>::reference std::vector<_Tp, _Alloc>::operator[](size_type) [with _Tp = unsigned char; _Alloc = std::allocator<unsigned char>; reference = unsigned char&; size_type = long unsigned int]: Assertion '_n < this->size()' failed.

Steps to Reproduce

This was added to the local.conf:
SECURITY_CFLAGS:append = " -D_GLIBCXX_ASSERTIONS"

Adding the define _GLIBCXX_ASSERTIONS ->
00125 #define __glibcxx_check_subscript(_N) \
00126 _GLIBCXX_DEBUG_VERIFY(_N < this->size(), \
00127 _M_message(::__gnu_debug::__msg_subscript_oob) \
00128 ._M_sequence(*this, "this") \
00129 ._M_integer(_N, #_N) \
00130 ._M_integer(this->size(), "size"))

_GLIBCXX_ASSERTIONS is new for LTS24 as far as I can tell. It will probably not crash if you don't have it defined.