Skip to content

dhcpcd/src/if-options.c:2120 SEGV by a READ memory access in parse_option #731

Description

@sigdevel

dhcpcd/src/if-options.c:2120 SEGV by a READ memory access in parse_option

Description:

A crafted conf-file supplied via dhcpcd -f <> can trigger a NULL-pointer dereference in parse_option() while parsing a custom option/variable definition. After the type token is consumed, the variable name is taken with "arg = strskipwhite(fp)"; strskipwhite() returns NULL when the remainder is empty or whitespace-only, and parse_option() then unconditionally calls "strcasecmp(arg, "reserved")" at if-options.c:2120 with arg == NULL. The NULL dereference crashes at if-options.c:2120.

To Reproduce

Steps to reproduce the behavior:

./dhcpcd -f ./5_if-options_c_2120 1> /dev/null

Output:

asan-build:

show full -click to expand
=================================================================
==1266523==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x559c0f7ab3e0 bp 0x7fff924f1570 sp 0x7fff924f0d20 T0)
==1266523==The signal is caused by a READ memory access.
==1266523==Hint: address points to the zero page.
    #0 0x559c0f7ab3e0 in strcasecmp (/run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/dhcpcd+0x6c3e0) (BuildId: b0997b3a3ac7480d192ccade97ea1fd3d69df25f)
    #1 0x559c0f8b163b in parse_option /run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/if-options.c:2120:8
    #2 0x559c0f8a2648 in parse_config_line /run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/if-options.c:2680:10
    #3 0x559c0f8a2648 in read_config /run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/if-options.c:3023:3
    #4 0x559c0f88aece in main /run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/dhcpcd.c:2271:8
    #5 0x7fa785f3bf76 in __libc_start_call_main csu/../sysdeps/nptl/libc_start_call_main.h:58:16
    #6 0x7fa785f3c026 in __libc_start_main csu/../csu/libc-start.c:360:3
    #7 0x559c0f78f8a0 in _start (/run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/dhcpcd+0x508a0) (BuildId: b0997b3a3ac7480d192ccade97ea1fd3d69df25f)

==1266523==Register values:
rax = 0x000000000f9a1001  rbx = 0x0000559c0f9a1020  rcx = 0x0000000000000001  rdx = 0x0000000000000001  
rdi = 0x0000000000000000  rsi = 0x0000559c0f9a1020  rbp = 0x00007fff924f1570  rsp = 0x00007fff924f0d20  
 r8 = 0x0000000000000000   r9 = 0x0000000000000005  r10 = 0x0000559c10362940  r11 = 0x00000fc370a34170  
r12 = 0x0000000000000000  r13 = 0x0000000000000000  r14 = 0x0000000000000000  r15 = 0x0000000000040000  
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV (/run/media/user/8ed8205b-4114-4c2a-b2d0-e2ad6640262d/dhcpcd/dhcpcd_asan/src/dhcpcd+0x6c3e0) (BuildId: b0997b3a3ac7480d192ccade97ea1fd3d69df25f) in strcasecmp
==1266523==ABORTING

Environment

OS: tested at 7.1.5-1kali1 (2026-07-29) x86_64 GNU/Linux ;
Compiler version: Clang 21.1.8 ;
Build-opts: -g -fno-omit-frame-pointer -fsanitize=address (AFL_USE_ASAN=1; ./configure --enable-debug --without-openssl) ;
CPU type: x86_64 ;
dhcpcd - commit hash 42ca579bc7aa6fbc6d1342eeade3eba028101a8b ;
dhcpcd verison - 10.5.2

Additional context

link to the sample (github-url):

5_if-options_c_2120

Screenshots

screen

screen

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions