dbus-marshal-validate: Validate length of arrays of fixed-length items
authorSimon McVittie <smcv@collabora.com>
Mon, 12 Sep 2022 12:14:18 +0000 (13:14 +0100)
committerSimon McVittie <smcv@collabora.com>
Wed, 5 Oct 2022 09:46:15 +0000 (10:46 +0100)
commit3b8a7aff228770f4f7b478db606b10cceacea875
treebf7922397e9611a8e5bb75014516485392d5bc1c
parent35d12acb0e249fae85221ca8c27c109e7a59c1cc
dbus-marshal-validate: Validate length of arrays of fixed-length items

This fast-path previously did not check that the array was made up
of an integer number of items. This could lead to assertion failures
and out-of-bounds accesses during subsequent message processing (which
assumes that the message has already been validated), particularly after
the addition of _dbus_header_remove_unknown_fields(), which makes it
more likely that dbus-daemon will apply non-trivial edits to messages.

Thanks: Evgeny Vereshchagin
Fixes: e61f13cf "Bug 18064 - more efficient validation for fixed-size type arrays"
Resolves: https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
Resolves: CVE-2022-42011
Signed-off-by: Simon McVittie <smcv@collabora.com>
(cherry picked from commit 079bbf16186e87fb0157adf8951f19864bc2ed69)
(cherry picked from commit b9e6a7523085a2cfceaffca7ba1ab4251f12a984)
dbus/dbus-marshal-validate.c