Branch: refs/heads/master
  Home:   https://github.com/OpenSIPS/opensips
  Commit: 71f682bca24b2fa155060209e47707c310101a52
      
https://github.com/OpenSIPS/opensips/commit/71f682bca24b2fa155060209e47707c310101a52
  Author: Norm Brandinger <[email protected]>
  Date:   2026-09-24 (Thu, 24 Sep 2026)

  Changed paths:
    M modules/b2b_entities/dlg.c

  Log Message:
  -----------
  b2b_entities: fix use-after-free of dialog keys in b2b_run_cb

b2b_run_cb() releases the bucket lock before invoking the registered
callback (the callback may re-enter b2b, so holding the lock would
deadlock). The callback arguments, however, were built by dereferencing
the dialog after the lock was dropped:

    B2BE_LOCK_RELEASE(table, hash_index);
    cb->cbf(entity_type,
        entity_type == B2B_SERVER ? &dlg->tag[1] : &dlg->callid,
        &dlg->logic_key, dlg->param, ...);

Those str arguments point into the dialog's shm. While the lock is
released, another process can delete the same dialog, so the callback
reads the entity key and logic key from freed memory.

Copy the entity key and logic key while still holding the lock and pass
the copies to the callback, so it never dereferences a dialog that may
have been freed. param is opaque to b2b and owned by the logic layer,
so it is safe to pass by value. This mirrors the deep-copy-under-lock
approach used for dialoginfo in 2a7c67358.

Refs #3985


  Commit: 46722d066712b3db2cdd402f270dd79d5a3f17c2
      
https://github.com/OpenSIPS/opensips/commit/46722d066712b3db2cdd402f270dd79d5a3f17c2
  Author: Răzvan Crainea <[email protected]>
  Date:   2026-09-29 (Tue, 29 Sep 2026)

  Changed paths:
    M modules/b2b_entities/dlg.c

  Log Message:
  -----------
  Merge pull request #4268 from NormB/fix/b2b-entities-run-cb-uaf

b2b_entities: copy callback keys before dropping the bucket lock in b2b_run_cb()


Compare: 
https://github.com/OpenSIPS/opensips/compare/b3cf52d2849c...46722d066712

To unsubscribe from these emails, change your notification settings at 
https://github.com/OpenSIPS/opensips/settings/notifications

_______________________________________________
Devel mailing list
[email protected]
http://lists.opensips.org/cgi-bin/mailman/listinfo/devel

Reply via email to