Project

General

Profile

Actions

Bug #4477

closed

Infinite loops in when using InspectionBufferMultipleForList

Added by Philippe Antoine over 1 year ago. Updated 12 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

From https://github.com/OISF/suricata/pull/5622#discussion_r626686822

POC is in #4476 once the buffer overflow gets fixed

Root cause is integer loss of precision casting local_id to uint16_t when there can more than 65536 buffers in a transaction

This may be not the case for dns.query as the maximum PDU length is 65536
But this is definitely the case for MQTT (subscribe topics) where Suricata default maximum PDU is 1Mbyte


Related issues 3 (0 open3 closed)

Related to Bug #4476: heap-buffer-overflow WRITE in InspectionBufferSetup with use of InspectionBufferGetMulti ClosedPhilippe AntoineActions
Copied to Security #4484: Infinite loops in when using InspectionBufferMultipleForListClosedShivani BhardwajActions
Copied to Security #4486: Infinite loops in when using InspectionBufferMultipleForListClosedJeff LucovskyActions
Actions

Also available in: Atom PDF