pespin submitted this change.

View Change

Approvals: Jenkins Builder: Verified osmith: Looks good to me, approved
ranap: Avoid write buffer overflow on GTPv1U outter IPv6 addr

If an IPv6 address was passed by libgtp in pdp->lib->gsnru,
sgsn_pdp_ctx_iu_rab_activate() would write 16 bytes to an uint32_t
variable, overflowing it and writing further on the stack.

The proper extended fix can be found in osmo-sgsn.git master branch
commit 6fd7c8b7fb0be7f96de7e7c5b4d22c54642f383a, this is a "backport" for
it fixing the security issue (write buffer overflow) in a simple way,
since the code has changed quite a lot in master.

Change-Id: Id521fbc904f847952736e8d63f77a616f1f8e838
Related: OS#7060
Reported-By: Adam Bedard <adam.bedard@gmail.com>
---
M src/sgsn/gprs_ranap.c
1 file changed, 5 insertions(+), 0 deletions(-)

diff --git a/src/sgsn/gprs_ranap.c b/src/sgsn/gprs_ranap.c
index 2ad663e..6f82850 100644
--- a/src/sgsn/gprs_ranap.c
+++ b/src/sgsn/gprs_ranap.c
@@ -236,6 +236,11 @@
use_x213_nsap = (uectx->rab_assign_addr_enc == RANAP_NSAP_ADDR_ENC_X213);

/* Get the IP address for ggsn user plane */
+ if (pdp->lib->gsnru.l != sizeof(ggsn_ip)) {
+ LOGPDPCTXP(LOGL_ERROR, pdp, "GSN-U address length %u unsupported\n",
+ pdp->lib->gsnru.l);
+ return -EINVAL;
+ }
memcpy(&ggsn_ip, pdp->lib->gsnru.v, pdp->lib->gsnru.l);
ggsn_ip = htonl(ggsn_ip);


To view, visit change 43342. To unsubscribe, or for help writing mail filters, visit settings.

Gerrit-MessageType: merged
Gerrit-Project: osmo-sgsn
Gerrit-Branch: pespin/rel-1.13.1
Gerrit-Change-Id: Id521fbc904f847952736e8d63f77a616f1f8e838
Gerrit-Change-Number: 43342
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <pespin@sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: osmith <osmith@sysmocom.de>
Gerrit-Reviewer: pespin <pespin@sysmocom.de>