From 0895397b2f90754eea929c181ddbc1129247a982 Mon Sep 17 00:00:00 2001 From: David Cermak Date: Thu, 18 Jun 2026 12:59:56 +0200 Subject: [PATCH 1/2] fix(lwip): reject invalid DHCP MTU option values Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes) before applying to netif->mtu, preventing rogue DHCP servers from setting MTU to 0 or other dangerously low values that cause integer wraparound in IPv4 fragmentation. --- components/lwip/port/hooks/lwip_default_hooks.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/components/lwip/port/hooks/lwip_default_hooks.c b/components/lwip/port/hooks/lwip_default_hooks.c index 6c094fdf047..6c7627ccc98 100644 --- a/components/lwip/port/hooks/lwip_default_hooks.c +++ b/components/lwip/port/hooks/lwip_default_hooks.c @@ -210,6 +210,9 @@ void dhcp_parse_extra_opts(struct dhcp *dhcp, uint8_t state, uint8_t option, uin NETIF_FOREACH(netif) { /* find the netif related to this dhcp */ if (dhcp == netif_dhcp_data(netif)) { + if (mtu < 68) { /* RFC 2132 requires MTU >= 68 */ + return; + } if (mtu < netif->mtu) { netif->mtu = mtu; LWIP_DEBUGF(DHCP_DEBUG | LWIP_DBG_TRACE, ("dhcp_parse_extra_opts(): Negotiated netif MTU is %d\n", netif->mtu)); From ecdf6ad91ca822aa12ece1cbce3c359e3dc3bed1 Mon Sep 17 00:00:00 2001 From: David Cermak Date: Tue, 23 Jun 2026 14:28:51 +0200 Subject: [PATCH 2/2] fix(lwip): Adds nullchecks after DHCP server alloc'd pools --- components/lwip/apps/dhcpserver/dhcpserver.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/components/lwip/apps/dhcpserver/dhcpserver.c b/components/lwip/apps/dhcpserver/dhcpserver.c index e7262d96829..9b7062a9301 100644 --- a/components/lwip/apps/dhcpserver/dhcpserver.c +++ b/components/lwip/apps/dhcpserver/dhcpserver.c @@ -1174,11 +1174,19 @@ static s16_t parse_msg(dhcps_t *dhcps, struct dhcps_msg *m, u16_t len) pnode = NULL; } else { pdhcps_pool = (struct dhcps_pool *)mem_calloc(1, sizeof(struct dhcps_pool)); + if (pdhcps_pool == NULL) { + return 0; + } pdhcps_pool->ip.addr = dhcps->client_address.addr; memcpy(pdhcps_pool->mac, m->chaddr, sizeof(pdhcps_pool->mac)); pdhcps_pool->lease_timer = lease_timer; pnode = (list_node *)mem_calloc(1, sizeof(list_node)); + if (pnode == NULL) { + mem_free(pdhcps_pool); + pdhcps_pool = NULL; + return 0; + } pnode->pnode = pdhcps_pool; pnode->pnext = NULL;