n0k0 has uploaded a new patch set (#3). ( https://gerrit.osmocom.org/c/osmo-iuh/+/42887?usp=email )
Change subject: iu_client: reject oversized RANAP NAS-PDU ......................................................................
iu_client: reject oversized RANAP NAS-PDU
The connection-oriented RANAP handlers ranap_handle_co_initial_ue() and ranap_handle_co_dt() copy the attacker-controlled NAS-PDU into a msgb allocated with a fixed 256 bytes. RANAP NAS-PDU is an unconstrained OCTET STRING, so the APER decoder accepts an arbitrarily large PDU; when nas_pdu.size exceeds the msgb tailroom, msgb_put() hits MSGB_ABORT and osmo_panic()s the process (MSGB_DEBUG is compiled in unconditionally), which a femtocell (HNB) peer can use to crash osmo-hnbgw / osmo-hnodeb by sending an InitialUE or DirectTransfer with a NAS-PDU > 256 bytes.
Validate nas_pdu.size against the msgb tailroom and drop the message gracefully instead of panicking.
This issue has been assigned the CVE candidate identifier CAN-2026-2051037.
Change-Id: I7dbce926477f9842cd466d46cda836638f04011f --- M src/iu_client.c 1 file changed, 12 insertions(+), 0 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/osmo-iuh refs/changes/87/42887/3