[dso] validate parsed TLV length in ProcessKeepAliveMessage() - #12609
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request significantly enhances the robustness and security of the DNS DSO connection by introducing critical size validation for TLV parsing within the Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Changelog
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request adds validation for the parsed TLV length in Dso::Connection::ProcessKeepAliveMessage() to prevent potential out-of-bounds reads. The changes are a good step towards improving security.
I've added one comment to further improve the parsing logic for the KeepAliveTlv. The current implementation reads a fixed size but advances the message offset by a variable size derived from the TLV's content, which can lead to parsing errors if the TLV is malformed. My suggestion is to enforce a length check that allows for future extensions, using a greater-than-or-equal comparison, and to use the known fixed size of the KeepAliveTlv structure for advancing the offset, making the parsing more robust and forward-compatible.
ProcessKeepAliveMessage()ProcessKeepAliveMessage()
Library files
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #12609 +/- ##
==========================================
- Coverage 75.64% 75.15% -0.49%
==========================================
Files 698 696 -2
Lines 95490 94520 -970
==========================================
- Hits 72235 71039 -1196
- Misses 23255 23481 +226
🚀 New features to boost your workflow:
|
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request effectively addresses a potential vulnerability in Dso::Connection::ProcessKeepAliveMessage() by replacing manual offset management with the OffsetRange class. This change enhances the robustness of TLV parsing, preventing out-of-bounds reads and potential infinite loops, and no new security vulnerabilities were identified. The implementation is well-done, with one suggestion to remove a redundant check for improved code clarity, aligning with best practices for avoiding unnecessary validations.
This commit updates the `Dso::Connection::ProcessKeepAliveMessage()` method to use the `OffsetRange` class for parsing TLVs. This approach robustly validates the size of each parsed TLV against the remaining length of the received message. Utilizing `OffsetRange::Contains()` ensures that the reported TLV size via `GetSize()` does not exceed the available bytes in the message, preventing potential out-of-bounds reads or infinite loops when iterating over subsequent TLVs.
This commit updates the
Dso::Connection::ProcessKeepAliveMessage()method to use theOffsetRangeclass for parsing TLVs. This approach robustly validates the size of each parsed TLV against the remaining length of the received message. UtilizingOffsetRange::Contains()ensures that the reported TLV size viaGetSize()does not exceed the available bytes in the message, preventing potential out-of-bounds reads or infinite loops when iterating over subsequent TLVs.Should help address #12602.