pespin has uploaded this change for review. ( 
https://gerrit.osmocom.org/c/libosmo-sigtran/+/43222?usp=email )


Change subject: xua: Avoid OOB read of Routing Context with len < 4
......................................................................

xua: Avoid OOB read of Routing Context with len < 4

Change-Id: If19f210c8d6a308f99b4f06fdc06581ffdc62696
---
M src/xua_shared.c
1 file changed, 5 insertions(+), 0 deletions(-)



  git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran 
refs/changes/22/43222/1

diff --git a/src/xua_shared.c b/src/xua_shared.c
index 51cbbf2..53b7337 100644
--- a/src/xua_shared.c
+++ b/src/xua_shared.c
@@ -42,6 +42,7 @@
 /* this is why we can use the M3UA constants below in a function shared 
between M3UA + SUA */
 osmo_static_assert(M3UA_ERR_INVAL_ROUT_CTX == SUA_ERR_INVAL_ROUT_CTX, 
_err_rctx);
 osmo_static_assert(M3UA_ERR_NO_CONFGD_AS_FOR_ASP == 
SUA_ERR_NO_CONFGD_AS_FOR_ASP, _err_as_for_asp);
+osmo_static_assert(M3UA_ERR_PARAM_FIELD_ERR == SUA_ERR_PARAM_FIELD_ERR, 
_err_param_field_err);

 /*! Find the AS for given ASP + optional routing context IE.
  *  if rctx_ie == NULL, we assume that this ASP is only part of a single AS;
@@ -58,6 +59,10 @@
        *as = NULL;

        if (rctx_ie) {
+               if (rctx_ie->len < 4) {
+                       LOGPASP(asp, log_ss, LOGL_ERROR, "%s(): Received 
Routing Context with len < 4\n", __func__);
+                       return M3UA_ERR_PARAM_FIELD_ERR;
+               }
                /* Use routing context IE to look up the AS for which the
                 * message was received. */
                uint32_t rctx = xua_msg_part_get_u32(rctx_ie);

--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43222?usp=email
To unsubscribe, or for help writing mail filters, visit 
https://gerrit.osmocom.org/settings?usp=email

Gerrit-MessageType: newchange
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: If19f210c8d6a308f99b4f06fdc06581ffdc62696
Gerrit-Change-Number: 43222
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <[email protected]>

Reply via email to