Fix OOB reads and infinite loop in TLV and DMAP parsers

pair_ap/pair-tlv.c (pair_tlv_parse):
- Add bounds check before reading type and length bytes (i + 2 > length)
- Fix off-by-one in chunked TLV scan loop (j + 1 < length)
- Add bounds checks inside data copy loop to prevent OOB memcpy
- Add else branch to advance index when size == 0 (prevents infinite loop)

rtsp.c (handle_set_parameter_metadata):
- Require 8 bytes remaining for tag + length fields (off + 8 <= cl)
- Validate value length against remaining buffer before read

Reported-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
This commit is contained in:
TristanInSec
2026-06-16 10:33:18 -04:00
parent b4751a09ef
commit 476677b0f0
2 changed files with 19 additions and 3 deletions
+4 -1
View File
@@ -3275,7 +3275,7 @@ static void handle_set_parameter_metadata(__attribute__((unused)) rtsp_conn_info
unsigned int off = 8;
uint32_t itag, vl;
while (off < cl) {
while (off + 8 <= cl) {
// pick up the metadata tag as an unsigned longint
memcpy(&itag, (uint32_t *)(cp + off), sizeof(uint32_t)); /* can be misaligned, thus memcpy */
itag = ntohl(itag);
@@ -3286,6 +3286,9 @@ static void handle_set_parameter_metadata(__attribute__((unused)) rtsp_conn_info
vl = ntohl(vl);
off += sizeof(uint32_t);
if (vl > cl - off)
break;
// pass the data over
if (vl == 0)
send_metadata('core', itag, NULL, 0, NULL, 1);