Skip to content

_modbus_receive_msg: use a deadline for the receive timeout - #882

Open
StalderT wants to merge 1 commit into
stephane:masterfrom
StalderT:fix/receive-deadline
Open

StalderT wants to merge 1 commit into
stephane:masterfrom
StalderT:fix/receive-deadline

Conversation

@StalderT

Copy link
Copy Markdown
Contributor

_modbus_receive_msg() passes the same timeval to every select() call and relies on select() to decrement it. Only Linux does that. On Windows, macOS and the BSDs the full timeout starts again after each received byte, so when the byte timeout is disabled a peer sending one byte just before each expiry keeps the receive going for as long as it wants (CVE-2026-51539).

The response or indication timeout now sets an absolute deadline on a monotonic clock, and each select() gets the time left. When the byte timeout is enabled nothing changes: it takes over after the first byte as before.

Fixes #843

_modbus_receive_msg() passes the same timeval to every select() call and relies on select() to decrement it. Only Linux does that. On Windows, macOS and the BSDs the full timeout starts again after each received byte, so when the byte timeout is disabled a peer sending one byte just before each expiry keeps the receive going for as long as it wants (CVE-2026-51539).

The response or indication timeout now sets an absolute deadline on a monotonic clock, and each select() gets the time left. When the byte timeout is enabled nothing changes: it takes over after the first byte as before.

Fixes stephane#843
@cla-bot

cla-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown

We require contributors to sign our Contributor License Agreement. In order for us to review and merge your code, please fill https://forms.gle/5635zjphDo5JEJQSA to get added. Your document will be manually checked by the maintainer. Be patient...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Slowloris-Style DoS in Modbus TCP Receive Path on Windows

1 participant