FINDING · DEPLOYMENT

The GFW's DNS packet injector (Injector 3, identified by TTL mirroring and zero IP ID) contained an out-of-bounds read vulnerability: due to missing label-length and null-terminator validation, malformed DNS requests caused the injector to copy adjacent stack memory into forged responses. Over three days in October 2023, researchers collected over 1 TB of data containing over 13 billion leaks, ~87.43% with non-duplicate content, including live Internet traffic transiting China's backbone and stack frames of the GFW's packet-handling processes.

From 2024-sakamoto-bleedingBleeding Wall: A Hematologic Examination on the Great Firewall · §3 Vulnerability · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dns-poisoningpacket-injectiondpi

Extracted by claude-sonnet-4-6 — review before relying.