From 021934e360585aa53352b73f9a0e0dbb0c9681e5 Mon Sep 17 00:00:00 2001 From: Robert Lubos Date: Thu, 6 Aug 2026 10:56:48 +0200 Subject: [PATCH] net: mdns_responder: Use static storage for listener poll arrays The socket service dispatcher stores the pointer to the poll fd array passed at registration and reuses it later (e.g. when a peer dispatcher on the same service is unregistered). The IPv6 and IPv4 poll arrays in init_listener() had automatic storage, so this stored pointer dangled once the function returned, leading to a stack-use-after-return. Move the arrays to file scope so they outlive the registration, as the LLMNR responder already does. Assisted-by: Cursor:claude-opus-4.8 Signed-off-by: Robert Lubos (cherry picked from commit ba0bd94d4e9bcc7dd77184f2921464585d88fd94) Signed-off-by: Mikey Sklar --- subsys/net/lib/dns/mdns_responder.c | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/subsys/net/lib/dns/mdns_responder.c b/subsys/net/lib/dns/mdns_responder.c index 5b6518499d23..3d8edc960bd1 100644 --- a/subsys/net/lib/dns/mdns_responder.c +++ b/subsys/net/lib/dns/mdns_responder.c @@ -224,6 +224,12 @@ static inline bool mdns_iface_is_enabled(struct net_if *iface) #if defined(CONFIG_NET_IPV4) static struct mdns_responder_context v4_ctx[MAX_IPV4_IFACE_COUNT]; +/* The socket service dispatcher keeps a pointer to the poll fd array passed at + * registration (and reuses it when a peer dispatcher is unregistered), so it + * must outlive init_listener(). Keep it at file scope for that reason. + */ +static struct zsock_pollfd ipv4_fds[MAX_IPV4_IFACE_COUNT]; + NET_SOCKET_SERVICE_SYNC_DEFINE_STATIC(v4_svc, dns_dispatcher_svc_handler, MDNS_V4_SVC_POLL_COUNT); #endif @@ -231,6 +237,9 @@ NET_SOCKET_SERVICE_SYNC_DEFINE_STATIC(v4_svc, dns_dispatcher_svc_handler, #if defined(CONFIG_NET_IPV6) static struct mdns_responder_context v6_ctx[MAX_IPV6_IFACE_COUNT]; +/* See the ipv4_fds comment above: the dispatcher retains this pointer. */ +static struct zsock_pollfd ipv6_fds[MAX_IPV6_IFACE_COUNT]; + NET_SOCKET_SERVICE_SYNC_DEFINE_STATIC(v6_svc, dns_dispatcher_svc_handler, MDNS_V6_SVC_POLL_COUNT); #endif @@ -1638,9 +1647,9 @@ static int init_listener(void) #if defined(CONFIG_NET_IPV6) /* Because there is only one IPv6 socket service context for all - * IPv6 sockets, we must collect the sockets in one place. + * IPv6 sockets, we must collect the sockets in one place (ipv6_fds, + * defined at file scope). */ - struct zsock_pollfd ipv6_fds[MAX_IPV6_IFACE_COUNT]; struct net_sockaddr_in6 local_addr6; int v6; @@ -1750,7 +1759,6 @@ static int init_listener(void) #endif /* CONFIG_NET_IPV6 */ #if defined(CONFIG_NET_IPV4) - struct zsock_pollfd ipv4_fds[MAX_IPV4_IFACE_COUNT]; struct net_sockaddr_in local_addr4; int v4;