nghttpx: Fix QUIC stateless reset stack buffer overflow

This commit is contained in:
Tatsuhiro Tsujikawa
2024-04-05 16:47:17 +09:00
parent 8b567c597a
commit dcc5d44094

View File

@@ -590,7 +590,7 @@ int QUICConnectionHandler::send_stateless_reset(
// SCID + minimum expansion - NGTCP2_STATELESS_RESET_TOKENLEN // SCID + minimum expansion - NGTCP2_STATELESS_RESET_TOKENLEN
constexpr size_t max_rand_byteslen = constexpr size_t max_rand_byteslen =
SHRPX_QUIC_SCIDLEN + 22 - NGTCP2_STATELESS_RESET_TOKENLEN; NGTCP2_MAX_CIDLEN + 22 - NGTCP2_STATELESS_RESET_TOKENLEN;
size_t rand_byteslen; size_t rand_byteslen;