pespin has submitted this change. ( https://gerrit.osmocom.org/c/osmo-sgsn/+/43323?usp=email )
Change subject: ranap: reject oversized RANAP NAS-PDU ......................................................................
ranap: reject oversized RANAP NAS-PDU
The connection-oriented RANAP handlers ranap_handle_co_initial_ue() and ranap_handle_co_dt() copy the attacker-controlled NAS-PDU into a msgb allocated with a fixed 256 bytes. RANAP NAS-PDU is an unconstrained OCTET STRING, so the APER decoder accepts an arbitrarily large PDU; when nas_pdu.size exceeds the msgb tailroom, msgb_put() hits MSGB_ABORT and osmo_panic()s the process (MSGB_DEBUG is compiled in unconditionally), which a femtocell (HNB) peer can use to crash osmo-hnbgw / osmo-hnodeb by sending an InitialUE or DirectTransfer with a NAS-PDU > 256 bytes.
Validate nas_pdu.size against the msgb tailroom and drop the message gracefully instead of panicking.
This issue has been assigned the CVE candidate identifier CAN-2026-2051037.
This is a backport from osmo-iuh.git f06967126f486bcb185ccf3d1a8f9bc02c4da1f6
Change-Id: I2090c7acbf861dfc295a82ef32a976ea7742438b --- M src/sgsn/gprs_ranap.c 1 file changed, 14 insertions(+), 0 deletions(-)
Approvals: Jenkins Builder: Verified osmith: Looks good to me, approved
diff --git a/src/sgsn/gprs_ranap.c b/src/sgsn/gprs_ranap.c index 70b1260..d80dcea 100644 --- a/src/sgsn/gprs_ranap.c +++ b/src/sgsn/gprs_ranap.c @@ -405,6 +405,13 @@ }
sai = asn1str_to_u16(&ies->sai.sAC); + if (ies->nas_pdu.size > msgb_tailroom(msg)) { + LOGP(DRANAP, LOGL_ERROR, + "RANAP InitialUE: NAS-PDU size %d > tailroom %d, dropping\n", + ies->nas_pdu.size, msgb_tailroom(msg)); + msgb_free(msg); + return -1; + } msgb_gmmh(msg) = msgb_put(msg, ies->nas_pdu.size); memcpy(msgb_gmmh(msg), ies->nas_pdu.buf, ies->nas_pdu.size);
@@ -510,6 +517,13 @@ } }
+ if (ies->nas_pdu.size > msgb_tailroom(msg)) { + LOGP(DRANAP, LOGL_ERROR, + "RANAP DirectTransfer: NAS-PDU size %d > tailroom %d, dropping\n", + ies->nas_pdu.size, msgb_tailroom(msg)); + msgb_free(msg); + return -1; + } msgb_gmmh(msg) = msgb_put(msg, ies->nas_pdu.size); memcpy(msgb_gmmh(msg), ies->nas_pdu.buf, ies->nas_pdu.size);