Re: [PATCH BlueZ v1 1/8] eir: Fix stack buffer overflow when parsing the remote name
Bastien Nocera <[email protected]>
| Newsgroups | org.kernel.vger.linux-bluetooth |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 2026-08-19 at 16:40 -0400, Luiz Augusto von Dentz wrote: > From: Luiz Augusto von Dentz <[email protected]> > > name2utf8() copies len bytes into a HCI_MAX_NAME_LENGTH + 2, so 250, > byte stack buffer without clamping len first. > > eir_parse() only rejects a field once it runs past the end of the EIR > data, and that data is up to 255 bytes, so field_len can be 254 and > the > data_len passed to name2utf8() can reach 253. strncpy() then writes > 253 > bytes into the 250 byte buffer and leaves it unterminated, so the > following g_strstrip() and g_strdup() also read past the end. > > The EIR data comes from a remote device, either in an extended > inquiry > response or in an advertising report, so the length is attacker > controlled. > > Clamp len like the other name2utf8() copies already do. Parsing a 253 > byte EIR_NAME_COMPLETE field returned a 253 byte name before this > change, and returns a 249 byte one after it. This issue was embargoed, and this commit is the exact same one I sent privately to fix that issue. It would be nice to have either the authored-by or co-authored by tag. Could you please also make sure to add: " Reported-by: @sprabhav7 (Prabhav S) See: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975 " To the commit message. I'll work on the security advisory to get it published. Cheers > > Assisted-by: Claude:claude-opus-5 > --- > src/eir.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/src/eir.c b/src/eir.c > index 89c15995a546..95351d015323 100644 > --- a/src/eir.c > +++ b/src/eir.c > @@ -137,6 +137,8 @@ static char *name2utf8(const uint8_t *name, > uint8_t len) > { > char utf8_name[HCI_MAX_NAME_LENGTH + 2]; > > + len = MIN(len, sizeof(utf8_name) - 1); > + > memset(utf8_name, 0, sizeof(utf8_name)); > strncpy(utf8_name, (char *) name, len); > strtoutf8(utf8_name, len);