summaryrefslogtreecommitdiffstats
path: root/meta/recipes-connectivity
diff options
context:
space:
mode:
authorVijay Anusuri <vanusuri@mvista.com>2024-05-10 12:30:02 +0530
committerSteve Sakoman <steve@sakoman.com>2024-05-16 05:22:09 -0700
commit688f3725d2bc14f1343d2d3fb9b13c58c1140089 (patch)
tree7e66a5a7b93e44343d6a7c0541e6ba3e78dda83a /meta/recipes-connectivity
parent0eea8a2194961f19006426738ce681ab722a52fd (diff)
downloadpoky-688f3725d2bc14f1343d2d3fb9b13c58c1140089.tar.gz
bluez5: Fix CVE-2023-27349 CVE-2023-50229 & CVE-2023-50230
Upstream-Status: Backport [https://github.com/bluez/bluez/commit/f54299a850676d92c3dafd83e9174fcfe420ccc9 & https://github.com/bluez/bluez/commit/5ab5352531a9cc7058cce569607f3a6831464443] (From OE-Core rev: adaebd54ea6f53bfbc093c3bdac4f02b0975cb15) Signed-off-by: Vijay Anusuri <vanusuri@mvista.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-connectivity')
-rw-r--r--meta/recipes-connectivity/bluez5/bluez5.inc2
-rw-r--r--meta/recipes-connectivity/bluez5/bluez5/CVE-2023-27349.patch48
-rw-r--r--meta/recipes-connectivity/bluez5/bluez5/CVE-2023-50229_CVE-2023-50230.patch67
3 files changed, 117 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/bluez5/bluez5.inc b/meta/recipes-connectivity/bluez5/bluez5.inc
index 7786b65670..97193a5f1c 100644
--- a/meta/recipes-connectivity/bluez5/bluez5.inc
+++ b/meta/recipes-connectivity/bluez5/bluez5.inc
@@ -55,6 +55,8 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/bluetooth/bluez-${PV}.tar.xz \
55 file://0001-tests-add-a-target-for-building-tests-without-runnin.patch \ 55 file://0001-tests-add-a-target-for-building-tests-without-runnin.patch \
56 file://0001-test-gatt-Fix-hung-issue.patch \ 56 file://0001-test-gatt-Fix-hung-issue.patch \
57 file://CVE-2023-45866.patch \ 57 file://CVE-2023-45866.patch \
58 file://CVE-2023-27349.patch \
59 file://CVE-2023-50229_CVE-2023-50230.patch \
58 " 60 "
59S = "${WORKDIR}/bluez-${PV}" 61S = "${WORKDIR}/bluez-${PV}"
60 62
diff --git a/meta/recipes-connectivity/bluez5/bluez5/CVE-2023-27349.patch b/meta/recipes-connectivity/bluez5/bluez5/CVE-2023-27349.patch
new file mode 100644
index 0000000000..946208099a
--- /dev/null
+++ b/meta/recipes-connectivity/bluez5/bluez5/CVE-2023-27349.patch
@@ -0,0 +1,48 @@
1From f54299a850676d92c3dafd83e9174fcfe420ccc9 Mon Sep 17 00:00:00 2001
2From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
3Date: Wed, 22 Mar 2023 11:34:24 -0700
4Subject: [PATCH] avrcp: Fix crash while handling unsupported events
5
6The following crash can be observed if the remote peer send and
7unsupported event:
8
9ERROR: AddressSanitizer: heap-use-after-free on address 0x60b000148f11
10 at pc 0x559644552088 bp 0x7ffe28b3c7b0 sp 0x7ffe28b3c7a0
11 WRITE of size 1 at 0x60b000148f11 thread T0
12 #0 0x559644552087 in avrcp_handle_event profiles/audio/avrcp.c:3907
13 #1 0x559644536c22 in control_response profiles/audio/avctp.c:939
14 #2 0x5596445379ab in session_cb profiles/audio/avctp.c:1108
15 #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)
16 #4 0x7fbcb3ea66c7 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0xaa6c7)
17 #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2)
18 #6 0x559644754ab6 in mainloop_run src/shared/mainloop-glib.c:66
19 #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188
20 #8 0x5596445bb963 in main src/main.c:1289
21 #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
22 #10 0x7fbcb3bafe3f in __libc_start_main_impl ../csu/libc-start.c:392
23 #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224)
24
25Upstream-Status: Backport [https://github.com/bluez/bluez/commit/f54299a850676d92c3dafd83e9174fcfe420ccc9]
26CVE: CVE-2023-27349
27Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
28---
29 profiles/audio/avrcp.c | 6 ++++++
30 1 file changed, 6 insertions(+)
31
32diff --git a/profiles/audio/avrcp.c b/profiles/audio/avrcp.c
33index 80f34c7a77..dda9a303fb 100644
34--- a/profiles/audio/avrcp.c
35+++ b/profiles/audio/avrcp.c
36@@ -3901,6 +3901,12 @@ static gboolean avrcp_handle_event(struct avctp *conn, uint8_t code,
37 case AVRCP_EVENT_UIDS_CHANGED:
38 avrcp_uids_changed(session, pdu);
39 break;
40+ default:
41+ if (event > AVRCP_EVENT_LAST) {
42+ warn("Unsupported event: %u", event);
43+ return FALSE;
44+ }
45+ break;
46 }
47
48 session->registered_events |= (1 << event);
diff --git a/meta/recipes-connectivity/bluez5/bluez5/CVE-2023-50229_CVE-2023-50230.patch b/meta/recipes-connectivity/bluez5/bluez5/CVE-2023-50229_CVE-2023-50230.patch
new file mode 100644
index 0000000000..92684d8210
--- /dev/null
+++ b/meta/recipes-connectivity/bluez5/bluez5/CVE-2023-50229_CVE-2023-50230.patch
@@ -0,0 +1,67 @@
1From 5ab5352531a9cc7058cce569607f3a6831464443 Mon Sep 17 00:00:00 2001
2From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
3Date: Tue, 19 Sep 2023 12:14:01 -0700
4Subject: [PATCH] pbap: Fix not checking Primary/Secundary Counter length
5
6Primary/Secundary Counters are supposed to be 16 bytes values, if the
7server has implemented them incorrectly it may lead to the following
8crash:
9
10=================================================================
11==31860==ERROR: AddressSanitizer: heap-buffer-overflow on address
120x607000001878 at pc 0x7f95a1575638 bp 0x7fff58c6bb80 sp 0x7fff58c6b328
13
14 READ of size 48 at 0x607000001878 thread T0
15 #0 0x7f95a1575637 in MemcmpInterceptorCommon(void*, int (*)(void const*, void const*, unsigned long), void const*, void const*, unsigned long) ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:860
16 #1 0x7f95a1575ba6 in __interceptor_memcmp ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:892
17 #2 0x7f95a1575ba6 in __interceptor_memcmp ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:887
18 #3 0x564df69c77a0 in read_version obexd/client/pbap.c:288
19 #4 0x564df69c77a0 in read_return_apparam obexd/client/pbap.c:352
20 #5 0x564df69c77a0 in phonebook_size_callback obexd/client/pbap.c:374
21 #6 0x564df69bea3c in session_terminate_transfer obexd/client/session.c:921
22 #7 0x564df69d56b0 in get_xfer_progress_first obexd/client/transfer.c:729
23 #8 0x564df698b9ee in handle_response gobex/gobex.c:1140
24 #9 0x564df698cdea in incoming_data gobex/gobex.c:1385
25 #10 0x7f95a12fdc43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)
26 #11 0x7f95a13526c7 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0xaa6c7)
27 #12 0x7f95a12fd2b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2)
28 #13 0x564df6977d41 in main obexd/src/main.c:307
29 #14 0x7f95a10a7d8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
30 #15 0x7f95a10a7e3f in __libc_start_main_impl ../csu/libc-start.c:392
31 #16 0x564df6978704 in _start (/usr/local/libexec/bluetooth/obexd+0x8b704)
32 0x607000001878 is located 0 bytes to the right of 72-byte region [0x607000001830,0x607000001878)
33
34 allocated by thread T0 here:
35 #0 0x7f95a1595a37 in __interceptor_calloc ../../../../src/libsanitizer/asan/asan_malloc_linux.cpp:154
36 #1 0x564df69c8b6a in pbap_probe obexd/client/pbap.c:1259
37
38Upstream-Status: Backport [https://github.com/bluez/bluez/commit/5ab5352531a9cc7058cce569607f3a6831464443]
39CVE: CVE-2023-50229 CVE-2023-50230
40Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
41---
42 obexd/client/pbap.c | 5 +++--
43 1 file changed, 3 insertions(+), 2 deletions(-)
44
45diff --git a/obexd/client/pbap.c b/obexd/client/pbap.c
46index 1ed8c68ecc..2d2aa95089 100644
47--- a/obexd/client/pbap.c
48+++ b/obexd/client/pbap.c
49@@ -285,7 +285,7 @@ static void read_version(struct pbap_data *pbap, GObexApparam *apparam)
50 data = value;
51 }
52
53- if (memcmp(pbap->primary, data, len)) {
54+ if (len == sizeof(pbap->primary) && memcmp(pbap->primary, data, len)) {
55 memcpy(pbap->primary, data, len);
56 g_dbus_emit_property_changed(conn,
57 obc_session_get_path(pbap->session),
58@@ -299,7 +299,8 @@ static void read_version(struct pbap_data *pbap, GObexApparam *apparam)
59 data = value;
60 }
61
62- if (memcmp(pbap->secondary, data, len)) {
63+ if (len == sizeof(pbap->secondary) &&
64+ memcmp(pbap->secondary, data, len)) {
65 memcpy(pbap->secondary, data, len);
66 g_dbus_emit_property_changed(conn,
67 obc_session_get_path(pbap->session),