n0k0 uploaded patch set #3 to this change.

View Change

iu_client: reject oversized RANAP NAS-PDU

The connection-oriented RANAP handlers ranap_handle_co_initial_ue() and
ranap_handle_co_dt() copy the attacker-controlled NAS-PDU into a msgb
allocated with a fixed 256 bytes. RANAP NAS-PDU is an unconstrained
OCTET STRING, so the APER decoder accepts an arbitrarily large PDU; when
nas_pdu.size exceeds the msgb tailroom, msgb_put() hits MSGB_ABORT and
osmo_panic()s the process (MSGB_DEBUG is compiled in unconditionally),
which a femtocell (HNB) peer can use to crash osmo-hnbgw / osmo-hnodeb
by sending an InitialUE or DirectTransfer with a NAS-PDU > 256 bytes.

Validate nas_pdu.size against the msgb tailroom and drop the message
gracefully instead of panicking.

This issue has been assigned the CVE candidate identifier
CAN-2026-2051037.

Change-Id: I7dbce926477f9842cd466d46cda836638f04011f
---
M src/iu_client.c
1 file changed, 12 insertions(+), 0 deletions(-)

git pull ssh://gerrit.osmocom.org:29418/osmo-iuh refs/changes/87/42887/3

To view, visit change 42887. To unsubscribe, or for help writing mail filters, visit settings.

Gerrit-MessageType: newpatchset
Gerrit-Project: osmo-iuh
Gerrit-Branch: master
Gerrit-Change-Id: I7dbce926477f9842cd466d46cda836638f04011f
Gerrit-Change-Number: 42887
Gerrit-PatchSet: 3
Gerrit-Owner: n0k0 <osmocom@hacky.software>