Skip to content

Validate encrypted connection request length before copying - #5875

Open
acts-1631 wants to merge 1 commit into
supertuxkart:masterfrom
acts-1631:fix-connection-request-length
Open

acts-1631 wants to merge 1 commit into
supertuxkart:masterfrom
acts-1631:fix-connection-request-length

Conversation

@acts-1631

@acts-1631 acts-1631 commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

ServerLobby::connectionRequested handles the first lobby packet before a peer is validated. It reads encrypted_size and passes data.getCurrentData() plus that attacker-controlled length to BareNetworkString, whose constructor calls memcpy without checking how many bytes remain.

A crafted connection request can make the server read past the ENet packet buffer during admission. Short bodies can also reach the crypto path with less data than the AES-GCM tag requires.

This change checks the selected tag size and requires encrypted_size to fit within the unread packet before copying. Invalid requests are logged and disconnected.

@acts-1631
acts-1631 force-pushed the fix-connection-request-length branch from 0429d83 to 35e7e25 Compare September 28, 2026 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant