What is considered a "padded" UDP package - when does it actually have no payload?

Viewed 43

I am trying to figure out when a UDP package is actually considered "empty", so it does not contain any payload. Let's just say I'm sending a UDP package to a Linux server and I'd like to test how it behaves when this package does not have any payload.

In Linux kernel version 5.0.0 it should lead to a DoS due to a out-of-bounds memory corruption. So since the kernel will assemble all received packages into one ( or multiple ) larger ones with GRO it will eventually need to do that with padded packages as well.

So when does a UDP package actually have no payload? The memory corruption will be caused due to a reference in the stack that does not match any data in the current socketbuffer ( due to the lack of it's payload ).

I'm just wondering how something can be created that is essentially"nothing". Preferably I want to create these packages in scapy. By the way here is the corresponding CVE: https://www.cvedetails.com/cve/CVE-2019-11683/

Oh if any of you are wondering: I am testing this on my own server, not trying to get sued or anything - I'm not performing this on a remote system.

0 Answers
Related