From d45d04dc430651d5467e04e302cab8d8c99e7146 Mon Sep 17 00:00:00 2001 From: David Cermak Date: Thu, 18 Jun 2026 12:59:56 +0200 Subject: [PATCH] fix(lwip): reject invalid DHCP MTU option values Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes) before applying to netif->mtu, preventing rogue DHCP servers from setting MTU to 0 or other dangerously low values that cause integer wraparound in IPv4 fragmentation. --- components/lwip/port/hooks/lwip_default_hooks.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/components/lwip/port/hooks/lwip_default_hooks.c b/components/lwip/port/hooks/lwip_default_hooks.c index 1ec6e75814f..ee5f5332e01 100644 --- a/components/lwip/port/hooks/lwip_default_hooks.c +++ b/components/lwip/port/hooks/lwip_default_hooks.c @@ -234,6 +234,9 @@ void dhcp_parse_extra_opts(struct dhcp *dhcp, uint8_t state, uint8_t option, uin NETIF_FOREACH(netif) { /* find the netif related to this dhcp */ if (dhcp == netif_dhcp_data(netif)) { + if (mtu < 68) { /* RFC 2132 requires MTU >= 68 */ + return; + } if (mtu < netif->mtu) { netif->mtu = mtu; LWIP_DEBUGF(DHCP_DEBUG | LWIP_DBG_TRACE, ("dhcp_parse_extra_opts(): Negotiated netif MTU is %d\n", netif->mtu));