From 486f0d7eb29993b1127ddc20017789da9ab87341 Mon Sep 17 00:00:00 2001 From: Mike Brady <4265913+mikebrady@users.noreply.github.com> Date: Thu, 18 Jun 2026 09:36:44 +0100 Subject: [PATCH] Update release notes with security bug fixes [skip ci] Documented fixes for two security issues in pair_ap/pair-tlv.c and rtsp.c, including bounds checks and validation improvements. Acknowledged contributions from TristanInSec for reporting and fixing the issues. --- RELEASENOTES-DEVELOPMENT.md | 20 +++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/RELEASENOTES-DEVELOPMENT.md b/RELEASENOTES-DEVELOPMENT.md index 1c0d4cc9..019c2c76 100644 --- a/RELEASENOTES-DEVELOPMENT.md +++ b/RELEASENOTES-DEVELOPMENT.md @@ -1,4 +1,22 @@ -Version +Version 5.1-dev-38-g3780b504 +== +**Bug Fixes** +* Fix two security issues reported in [#2215](https://github.com/mikebrady/shairport-sync/issues/2215) and [#2216](https://github.com/mikebrady/shairport-sync/issues/2216): + + **pair_ap/pair-tlv.c** (`pair_tlv_parse`): + - Add bounds check before reading type and length bytes + - Fix off-by-one in chunked TLV scan loop + - Add bounds checks inside data copy loop to prevent OOB memcpy + - Add else branch to advance index when size == 0 (prevents infinite loop) + + **rtsp.c** (`handle_set_parameter_metadata`): + - Require 8 bytes remaining for tag + length fields + - Validate value length against remaining buffer before read + +Many thanks to [TristanInSec](https://github.com/TristanInSec) for reporting the issues and for the [PR](https://github.com/mikebrady/shairport-sync/pull/2218) to fix the problem. + + +Version 5.1-dev-36-gb4751a09 == **Bug Fix** * When an immediate flush is requested, reset the PTP clock anchor information _immediately_ to disable clocking until play is resumed. This prevents occasional apparent sudden jumps in the timing of frames of audio due to using an obsolete clock. It was causing no known problems.