pespin has submitted this change. ( 
https://gerrit.osmocom.org/c/libosmo-sigtran/+/43421?usp=email )

Change subject: sua: sua_addr_parse_part(): Fix potential read buffer overflow
......................................................................

sua: sua_addr_parse_part(): Fix potential read buffer overflow

The sua_addr_parse_part() function lacked validating that the length
value in the TLV struct didn't go past the buffer, which could end up in
a read buffer overflow.

Related: OS#7079
Reported-By: Tristan Madani <[email protected]>
Change-Id: I12fbdfc37bfbf6cf9ba18942eb0ec43c9d1349fe
---
M src/sua.c
1 file changed, 4 insertions(+), 1 deletion(-)

Approvals:
  Jenkins Builder: Verified
  laforge: Looks good to me, approved
  osmith: Looks good to me, but someone else must approve




diff --git a/src/sua.c b/src/sua.c
index 3b217f4..0784b61 100644
--- a/src/sua.c
+++ b/src/sua.c
@@ -830,9 +830,12 @@
                par_tag = ntohs(par->tag);
                par_len = ntohs(par->len);

-               /* sanity: check par->len received on the wire, make sure the 
subtraction does not wrap past zero. */
+               /* L value must account for at least TL (struct 
xua_parameter_hdr): */
                if (par_len < sizeof(*par))
                        goto subpar_fail;
+               /* Avoid reading past buffer: */
+               if (pos + par_len > param->len)
+                       goto subpar_fail;
                par_datalen = par_len - sizeof(*par);

                LOGP(DLSUA, LOGL_DEBUG, "SUA IEI 0x%04x pos %hu/%hu: subpart 
tag 0x%04x, len %hu\n",

--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43421?usp=email
To unsubscribe, or for help writing mail filters, visit 
https://gerrit.osmocom.org/settings?usp=email

Gerrit-MessageType: merged
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I12fbdfc37bfbf6cf9ba18942eb0ec43c9d1349fe
Gerrit-Change-Number: 43421
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <[email protected]>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <[email protected]>
Gerrit-Reviewer: laforge <[email protected]>
Gerrit-Reviewer: osmith <[email protected]>
Gerrit-Reviewer: pespin <[email protected]>

Reply via email to