Attention is currently required from: jolly.
dexter has posted comments on this change by jolly. ( https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/42969?usp=email )
Change subject: IPAd: Update nvstate.bin to SGP.32 Version 1.2
......................................................................
Patch Set 5:
(1 comment)
Patchset:
PS5:
> This patch illustrates the problem with nvstate.bin quite well. If you use a prepared nvstate. […]
As far as I can see we do not have to do anything actively to generate the nvstate.bin. onomondo-ipa will generate it automatically when it is missing. So you can just remove it and everything should still work fine.
Unlike with the IoT emulation, we use for manual testing, we do not have to load any initial EIM configuration. The EIM configuration is read from the card, which means it comes from the testsuite directly via ES10.
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/42969?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: I3d22980f5f8be546f0d80423b3bd80d197aa8872
Gerrit-Change-Number: 42969
Gerrit-PatchSet: 5
Gerrit-Owner: jolly <andreas(a)eversberg.eu>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Attention: jolly <andreas(a)eversberg.eu>
Gerrit-Comment-Date: Tue, 18 Aug 2026 14:54:54 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: dexter <pmaier(a)sysmocom.de>
fixeria has submitted this change. ( https://gerrit.osmocom.org/c/libosmo-sigtran/+/43228?usp=email )
Change subject: sua: fix buffer overflow in sua_parse_gt()
......................................................................
sua: fix buffer overflow in sua_parse_gt()
RFC 3868 does not impose a limit on the Number of Digits, so ideally
we should be able to parse up to 255 digits. However, our
gt->digits[] can only fit up to 31 digits + a terminating NUL.
Cap num_digits to the size of gt->digits before decoding and parse
as much as we can, returning -ENOSPC if not all digits fit. Add a
unit test covering both the exact-fit and oversized num_digits cases.
Change-Id: I59f601f2d8706748797c802f0f09887e4b9ba31f
Reported-By: 3ntr0py1337
Fixes: OS#7046
---
M src/sua.c
M tests/xua/xua_test.c
M tests/xua/xua_test.ok
3 files changed, 42 insertions(+), 1 deletion(-)
Approvals:
fixeria: Looks good to me, approved
pespin: Looks good to me, but someone else must approve
laforge: Looks good to me, but someone else must approve
Jenkins Builder: Verified
diff --git a/src/sua.c b/src/sua.c
index f5dcd66..35c4a8e 100644
--- a/src/sua.c
+++ b/src/sua.c
@@ -383,12 +383,14 @@
* \param[out] gt User-allocated structure for decoded output
* \param[in] data binary-encoded data
* \param[in] datalen length of \ref data in octets
+ * \returns 0 on success; negative on error
*/
int sua_parse_gt(struct osmo_sccp_gt *gt, const uint8_t *data, unsigned int datalen)
{
uint8_t num_digits;
char *out_digits;
unsigned int i;
+ int rc = 0;
/* 8 byte header at minimum, plus digits */
if (datalen < 8)
@@ -401,6 +403,15 @@
gt->npi = data[6];
gt->nai = data[7];
+ /* XXX: RFC 3868 does not impose a limit on the Number of Digits, so
+ * ideally we should be able to parse up to 255 digits. However, our
+ * gt->digits[] can only fit up to 31 digits + a terminating NUL. */
+ if (num_digits > sizeof(gt->digits) - 1) {
+ /* Parse as much as we can; return -ENOSPC */
+ num_digits = sizeof(gt->digits) - 1;
+ rc = -ENOSPC;
+ }
+
/* parse digits */
out_digits = gt->digits;
for (i = 0; i < datalen-8; i++) {
@@ -414,7 +425,7 @@
}
*out_digits++ = '\0';
- return 0;
+ return rc;
}
/*! \brief parse SCCP address from given xUA message part
diff --git a/tests/xua/xua_test.c b/tests/xua/xua_test.c
index 3c5f5fd..dcd2089 100644
--- a/tests/xua/xua_test.c
+++ b/tests/xua/xua_test.c
@@ -372,6 +372,31 @@
msgb_free(msg);
}
+static void test_sua_parse_gt_overflow(void)
+{
+ /* 8-byte header + way more digit octets than fit into gt->digits[32] */
+ uint8_t data[8 + 64];
+ struct osmo_sccp_gt gt = {};
+
+ memset(data, 0x11, sizeof(data));
+ data[3] = 0x42; /* gti */
+ data[5] = 0x00; /* tt */
+ data[6] = 0x01; /* npi */
+ data[7] = 0x04; /* nai */
+
+ data[4] = sizeof(gt.digits); /* num_digits: not enough room for '\0' */
+ printf("Testing sua_parse_gt() with num_digits=%u\n", data[4]);
+ OSMO_ASSERT(sua_parse_gt(>, data, sizeof(data)) == -ENOSPC);
+ OSMO_ASSERT(strlen(gt.digits) == sizeof(gt.digits) - 1);
+ printf("OUT:%s\n", osmo_sccp_gt_dump(>));
+
+ data[4] = 0xff; /* num_digits: way too large */
+ printf("Testing sua_parse_gt() with num_digits=%u\n", data[4]);
+ OSMO_ASSERT(sua_parse_gt(>, data, sizeof(data)) == -ENOSPC);
+ OSMO_ASSERT(strlen(gt.digits) == sizeof(gt.digits) - 1);
+ printf("OUT:%s\n", osmo_sccp_gt_dump(>));
+}
+
/* SCCP Message Transcoding */
struct sccp2sua_testcase {
@@ -679,6 +704,7 @@
test_isup_parse();
test_sccp_addr_parser();
test_helpers();
+ test_sua_parse_gt_overflow();
test_sccp2sua();
test_rkm();
test_sccp_addr_encdec();
diff --git a/tests/xua/xua_test.ok b/tests/xua/xua_test.ok
index 02e5f49..f6f30d6 100644
--- a/tests/xua/xua_test.ok
+++ b/tests/xua/xua_test.ok
@@ -16,6 +16,10 @@
0400000001000000040000003931393936393637393338390000000000000000000000000000000000000000
OUT:TT=0,NPL=1,NAI=4,DIG=919969679389
0400000001000000040000003931393936393637393338390000000000000000000000000000000000000000
+Testing sua_parse_gt() with num_digits=32
+OUT:DIG=1111111111111111111111111111111
+Testing sua_parse_gt() with num_digits=255
+OUT:DIG=1111111111111111111111111111111
=> BSSMAP-RESET
SCCP Input: [L2]> 09 00 03 05 07 02 42 fe 02 42 fe 06 00 04 30 04 01 20
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43228?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: merged
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I59f601f2d8706748797c802f0f09887e4b9ba31f
Gerrit-Change-Number: 43228
Gerrit-PatchSet: 3
Gerrit-Owner: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Attention is currently required from: jolly, osmith.
laforge has posted comments on this change by jolly. ( https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/42967?usp=email )
Change subject: IPAd: Make tests work with testenv and current master of IPAd
......................................................................
Patch Set 5: -Code-Review
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/42967?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: Id4abf15feb179b17594bd11c6e7089469684900c
Gerrit-Change-Number: 42967
Gerrit-PatchSet: 5
Gerrit-Owner: jolly <andreas(a)eversberg.eu>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: jolly <andreas(a)eversberg.eu>
Gerrit-Comment-Date: Tue, 18 Aug 2026 14:49:19 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
fixeria has submitted this change. ( https://gerrit.osmocom.org/c/libosmocore/+/43232?usp=email )
Change subject: gsm/ipa: fix t_len truncation in ipa_ccm_id_resp_parse()
......................................................................
gsm/ipa: fix t_len truncation in ipa_ccm_id_resp_parse()
The IPA CCM ID RESP TLV format uses a 16bit length field, and
osmo_load16be() is used to read it, but t_len was declared as
uint8_t, silently truncating any length above 255.
Change-Id: I86392c51235faa2d985ac82b04a9681ae176ad99
Related: OS#7050
---
M src/gsm/ipa.c
1 file changed, 1 insertion(+), 1 deletion(-)
Approvals:
fixeria: Looks good to me, approved
Jenkins Builder: Verified
laforge: Looks good to me, but someone else must approve
pespin: Looks good to me, but someone else must approve
diff --git a/src/gsm/ipa.c b/src/gsm/ipa.c
index 50fa31f..3e631de 100644
--- a/src/gsm/ipa.c
+++ b/src/gsm/ipa.c
@@ -209,7 +209,7 @@
* \returns 0 on success; negative on error */
int ipa_ccm_id_resp_parse(struct tlv_parsed *dec, const uint8_t *buf, unsigned int len)
{
- uint8_t t_len;
+ uint16_t t_len;
uint8_t t_tag;
const uint8_t *cur = buf;
--
To view, visit https://gerrit.osmocom.org/c/libosmocore/+/43232?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: merged
Gerrit-Project: libosmocore
Gerrit-Branch: master
Gerrit-Change-Id: I86392c51235faa2d985ac82b04a9681ae176ad99
Gerrit-Change-Number: 43232
Gerrit-PatchSet: 2
Gerrit-Owner: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
fixeria has submitted this change. ( https://gerrit.osmocom.org/c/libosmocore/+/43235?usp=email )
Change subject: gsm0480: fix out-of-bounds reads in parse_ss_{invoke,return_result}()
......................................................................
gsm0480: fix out-of-bounds reads in parse_ss_{invoke,return_result}()
Both Facility component parsers checked 'offset' against 'length' one
(or two) bytes short of the index they went on to dereference, and
parse_ss_invoke() never re-validated 'offset' after skipping the
optional Linked ID, whose skip length is attacker-controlled. The same
off-by-one on the operation-code path also let "length - offset - 3"
underflow a uint16_t, handing parse_process_uss_req() a bogus,
oversized length that bypassed its own bounds check and grew the
over-read into a memcpy() into req->ussd_data/req->ussd_text.
Tighten each guard to cover the index actually dereferenced, and
re-check 'offset' against 'length' after the Linked ID skip and after
the post-SEQUENCE-tag increment in parse_ss_return_result().
Change-Id: I59fe4df8045dbe1e2b9509330527408b84abf2e4
Reported-By: Adam Bedard <adam.bedard(a)gmail.com>
Fixes: OS#7051
---
M src/gsm/gsm0480.c
1 file changed, 15 insertions(+), 6 deletions(-)
Approvals:
laforge: Looks good to me, but someone else must approve
pespin: Looks good to me, but someone else must approve
Jenkins Builder: Verified
fixeria: Looks good to me, approved
diff --git a/src/gsm/gsm0480.c b/src/gsm/gsm0480.c
index a8eac6b..5db5bed 100644
--- a/src/gsm/gsm0480.c
+++ b/src/gsm/gsm0480.c
@@ -548,17 +548,24 @@
offset = invoke_data[1] + 2;
req->invoke_id = invoke_data[2];
- /* look ahead once */
- if (offset + 1 > length)
+ /* look ahead once: need invoke_data[offset] and, if it turns out to be
+ * the optional Linked ID tag, invoke_data[offset+1] as well */
+ if (offset + 2 > length)
return 0;
/* optional part */
- if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID)
+ if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID) {
offset += invoke_data[offset+1] + 2; /* skip over it */
+ /* offset moved by an attacker-controlled amount: re-validate */
+ if (offset >= length)
+ return 0;
+ }
+
/* mandatory part */
if (invoke_data[offset] == GSM0480_OPERATION_CODE) {
- if (offset + 2 > length)
+ /* need invoke_data[offset+2] below, and length - offset - 3 must not underflow */
+ if (offset + 3 > length)
return 0;
uint8_t operation_code = invoke_data[offset+2];
req->opcode = operation_code;
@@ -624,10 +631,12 @@
if (rr_data[offset] != GSM_0480_SEQUENCE_TAG)
return 0;
- if (offset + 2 > length)
+ offset += 2;
+
+ /* need rr_data[offset+2] below, and length - offset - 3 must not underflow */
+ if (offset + 3 > length)
return 0;
- offset += 2;
operation_code = rr_data[offset + 2];
req->opcode = operation_code;
--
To view, visit https://gerrit.osmocom.org/c/libosmocore/+/43235?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: merged
Gerrit-Project: libosmocore
Gerrit-Branch: master
Gerrit-Change-Id: I59fe4df8045dbe1e2b9509330527408b84abf2e4
Gerrit-Change-Number: 43235
Gerrit-PatchSet: 2
Gerrit-Owner: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Attention is currently required from: jolly.
dexter has posted comments on this change by jolly. ( https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43267?usp=email )
Change subject: Add log message for unexpected result in PIPEasp function
......................................................................
Patch Set 1: Code-Review+2
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43267?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: Ic20f4b23050940348879512d6c8b78c1ae70e75d
Gerrit-Change-Number: 43267
Gerrit-PatchSet: 1
Gerrit-Owner: jolly <andreas(a)eversberg.eu>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Attention: jolly <andreas(a)eversberg.eu>
Gerrit-Comment-Date: Tue, 18 Aug 2026 14:47:01 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
Attention is currently required from: pespin.
fixeria has posted comments on this change by fixeria. ( https://gerrit.osmocom.org/c/libosmocore/+/43232?usp=email )
Change subject: gsm/ipa: fix t_len truncation in ipa_ccm_id_resp_parse()
......................................................................
Patch Set 1: Code-Review+2
(1 comment)
File src/gsm/ipa.c:
https://gerrit.osmocom.org/c/libosmocore/+/43232/comment/2ba28f45_c9e70f94?… :
PS1, Line 212: uint16_t t_len;
> Waoh so ipa_ccm_id_resp_parse() has a 2 byte len and ipa_ccm_id_get_parse() has a 1 byte len?
Yes. See also the payload format in doxygen comments above.
For this function it's "16bit length value (length of payload *and tag*)".
--
To view, visit https://gerrit.osmocom.org/c/libosmocore/+/43232?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: libosmocore
Gerrit-Branch: master
Gerrit-Change-Id: I86392c51235faa2d985ac82b04a9681ae176ad99
Gerrit-Change-Number: 43232
Gerrit-PatchSet: 1
Gerrit-Owner: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Gerrit-Attention: pespin <pespin(a)sysmocom.de>
Gerrit-Comment-Date: Tue, 18 Aug 2026 14:46:20 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: Yes
Comment-In-Reply-To: pespin <pespin(a)sysmocom.de>
Attention is currently required from: jolly.
dexter has posted comments on this change by jolly. ( https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43266?usp=email )
Change subject: Add start and stop functions to PIPEasp
......................................................................
Patch Set 1: Code-Review+1
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43266?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: I5be804e5fa7b9a135cceaf07ac4157895a222b40
Gerrit-Change-Number: 43266
Gerrit-PatchSet: 1
Gerrit-Owner: jolly <andreas(a)eversberg.eu>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: dexter <pmaier(a)sysmocom.de>
Gerrit-Attention: jolly <andreas(a)eversberg.eu>
Gerrit-Comment-Date: Tue, 18 Aug 2026 14:41:41 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes