Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table store
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS 벡터 정보 없음
약점 (CWE)
- CWE-787
경계 밖 쓰기 — 버퍼 범위를 벗어난 메모리에 써서 충돌·코드 실행으로 이어질 수 있음.
상세 설명
Any host on the LAN can send two mDNS records and make the responder write past the end of its
transmit packet.
The string table stores each name in a slot rounded up to a multiple of four:
1 2 3 4/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ 5 6 7 8memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF; 9 10 11 12...13 14 15 16len = *((USHORT*)(p - 2)); /* slot size, not string length */17 18 19 20if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)21 22 The lookup that decides whether an incoming name is already stored compares the rounded slot size,
so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered
with the pointer to the first, and the record then carries a string up to three bytes longer than
the length the caller accounted for. _nx_mdns_packet_rr_add (nxd_mdns.c:8911) sizes its only
bound check from that stale length, and _nx_mdns_name_string_encode writes the real string.
Two PTR records are enough, both ordinary mDNS responses to a _http._tcp query, with owner names
whose lengths fall in the same bucket:
1 2 3 4==87491==ERROR: AddressSanitizer: heap-buffer-overflow 5 6 7 8WRITE of size 1 at 0x611000000124 thread T5 9 10 #0 _nx_mdns_name_string_encode addons/mdns/nxd_mdns.c:1309611 #1 _nx_mdns_packet_rr_add addons/mdns/nxd_mdns.c:891112 13 140x611000000124 is 0 bytes to the right of 228-byte region15 16 The overflow is one to three bytes of attacker-influenced name data past nx_packet_data_end. In a
normal pool that lands in the next packet in the same pool rather than in a redzone, so the visible
effect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.
Compare the slot size against the stored string length before declaring a match, or keep the
string length in the slot header and return it to the caller so the encoder and the bound check
agree.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.