dbus-marshal-validate: Validate length of arrays of fixed-length items 86/288486/1
authorSimon McVittie <smcv@collabora.com>
Mon, 12 Sep 2022 12:14:18 +0000 (13:14 +0100)
committerUnsung Lee <unsung.lee@samsung.com>
Fri, 17 Feb 2023 06:33:28 +0000 (15:33 +0900)
commit15b41b7b4c8f6c940ed25dc56f920b988c8065b6
treef2b8b636c6ab8397ae77492569b2874f534970b3
parent1962bd7b478b21ae054b836f41e944f2a45f6621
dbus-marshal-validate: Validate length of arrays of fixed-length items

This fast-path previously did not check that the array was made up
of an integer number of items. This could lead to assertion failures
and out-of-bounds accesses during subsequent message processing (which
assumes that the message has already been validated), particularly after
the addition of _dbus_header_remove_unknown_fields(), which makes it
more likely that dbus-daemon will apply non-trivial edits to messages.

Thanks: Evgeny Vereshchagin
Fixes: e61f13cf "Bug 18064 - more efficient validation for fixed-size type arrays"
Resolves: https://gitlab.freedesktop.org/dbus/dbus/-/issues/413
Resolves: CVE-2022-42011
Signed-off-by: Simon McVittie <smcv@collabora.com>
(cherry picked from commit 079bbf16186e87fb0157adf8951f19864bc2ed69)
(cherry picked from commit b9e6a7523085a2cfceaffca7ba1ab4251f12a984)
Signed-off-by: Unsung Lee <unsung.lee@samsung.com>
Change-Id: Idfe8cead0721c414f1e6946a5dc0544bad63d42e
dbus/dbus-marshal-validate.c