В ядре Linux устранена следующая уязвимость:
Bluetooth: eir: исправлено чтение OOB в eir_get_service_data().
eir_get_service_data() просматривает рекламные данные для служебных данных.
поле с соответствующим UUID. При несоответствии он продвигается:
эйр += длэн;
eir_len -= дллен;
eir_get_data() сообщает dlen как длину данных поля, но поле
охватывает dlen + 2 байта после подсчета длины и типа и т. д.
когда для его достижения были пропущены поля, не относящиеся к служебным данным. Указатель
правильно приземляется на следующем поле. eir_len нет, и недостаток
объединяет поля до тех пор, пока eir_get_data() не прочитает длину и тип
байты «поля» за концом буфера.
Для широковещательного приемника ISO этот буфер имеет вид hcon->le_per_adv_data[], заполненный.
из периодических рекламных репортажей удаленной телекомпании. ПА
полезная нагрузка, заполненная несовпадающими полями служебных данных, уходит из массива
в остальную часть структуры hci_conn. Дрейфующее поле, соответствующее BAA
UUID помещает эти байты в iso_pi(sk)->base, где их считывает пользовательское пространство.
обратно с помощью gotockopt(BT_ISO_BASE).
Пересчитывайте eir_len из конца буфера на каждой итерации.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_data() eir_get_service_data() walks the advertising data for a Service Data field with a matching UUID. On a mismatch it advances: eir += dlen; eir_len -= dlen; eir_get_data() reports dlen as the field's data length, but the field spans dlen + 2 bytes once its length and type bytes count, and more when non-Service-Data fields were skipped to reach it. The pointer lands correctly on the next field. eir_len does not, and the shortfall compounds across fields until eir_get_data() reads the length and type bytes of a "field" past the end of the buffer. For an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled from the periodic advertising reports of a remote broadcaster. A PA payload packed with mismatching Service Data fields walks off the array into the rest of struct hci_conn. A drifted field that matches the BAA UUID puts those bytes in iso_pi(sk)->base, where user space reads them back with getsockopt(BT_ISO_BASE). Recompute eir_len from the end of the buffer each iteration.
Характеристики атаки
Последствия
Строка CVSS v3.1