Verify the URI length provided to lwm2m_pull_context_start_transfer()
before use, otherwise in case the URI string is longer than the buffer,
only part of it was copied w/o NULL terminator, which could lead to
out-of-bound reads and other undefined behavior.
As the string length is now validated, just use strcpy() instead of
memcpy(), no need to copy the whole buffer.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 99a164df5c)
In case socket is closed during an async TCP handshake, the TCP context
should be closed immediately, otherwise the connection could be
established after the socket was closed, causing TCP context leak.
To avoid race between socket close and resend timer (i.e. socket being
closed at the same time as the retransmission limit is reached), add
extra state checks before attempting to close the TCP context.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 8588b08808)
Add a test case which verifies that if a client socket is closed during
an async handshake, the TCP context is properly cleaned up on close,
i.e. it no longer tries to establish the connection.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 4e830615a2)
validate the assumptions about buffers returned by alloc_buf() in the
LE CoC receive path.
if the returned buffer does not provide enough user_data space for the
internal segment counter, disconnect and drop the buffer instead of
reading or writing past the metadata area.
also document that alloc_buf() must return a buffer with at least
sizeof(uint16_t) bytes of user_data.
Signed-off-by: Oleh Konko <security@1seal.org>
(cherry picked from commit 09ad7174e9)
If the (addr + size) overflows the memory address space,
the inner loop may not run to check for permission. Since
the default return value was 0 (meaning permitted), it
would incorrectly say memory access was okay. Fix this by
changing the default return value to -EINVAL. Only after
the loop of validating the whole input address range then
we set the return value to 0 to say memory access is
permitted. Also check for addition overflow.
Signed-off-by: Daniel Leung <daniel.leung@intel.com>
(cherry picked from commit 3b1bdaf548)
The comment is correct, the code was wrong. Each chunk can be 64 bytes of
data, but they also have 4 byte headers. So to be able to read 255 chunks
with 64 bytes of data each, The buffer has to be 255 * 68.
Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit c98321cbfe)
ffa_create_top() was opening files with FS_O_CREATE | FS_O_WRITE
only, which caused host applications like 'cat' to fail with
Permission denied when trying to read the file through FUSE. This
is because FAT filesystem explicitly checks the READ flag before
allowing read access.
Fix by replacing FS_O_WRITE with FS_O_RDWR so the file is opened
with both read and write access.
Signed-off-by: Surya Prakash T <suryat@aerlync.com>
(cherry picked from commit 8f959ad0e6)
The limit check on mq_attr used && instead of ||, so a request
exceeding only one of CONFIG_MSG_SIZE_MAX or CONFIG_POSIX_MQ_OPEN_MAX
was accepted. The buffer was then allocated as
msg_size * max_msgs without overflow checking, allowing the
multiplication to wrap and produce an under-sized heap buffer
that a later mq_send() would overflow.
Reject when either limit is exceeded, and use size_mul_overflow()
before k_malloc().
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 8a1fe0f6ad)
Reject malformed nrf_wifi_umac_event_power_save_info payloads before
copying TWT entries into struct wifi_ps_config. The handler previously
trusted num_twt_flows and indexed twt_flow_info[] without checking
WIFI_MAX_TWT_FLOWS or event_len, which could overflow the fixed Zephyr
twt_flows buffer and read past the event buffer.
Fix issue #108848.
Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Cursor:Auto
(cherry picked from commit a2c4324acd)
Run address sanitizer to catch any undefined behavior issues
in the code.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d5ced71a8c)
Use memcmp() to compare values instead of direct comparison.
Without this, some of the tests were failing because this
comparison "" != "" was true when ASAN was enabled.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 007a274258)
The test code accessed buffer outside of limits. Fix it by
setting the string length properly in the test.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 2df51049e4)
Make sure that IPv6 address parsing works as expected.
Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c79d0c467)
Make sure we will not overflow the ipaddress buffer if
port number is given.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 6e119a636a)
Make sure that IPv4 address parsing works as expected.
Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d1b52d078f)
Make sure we will not overflow the ipaddress buffer if
port number is given.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c8d19a51f)
Add bounds checking to PTP management interval parameters to prevent
undefined behavior from bitwise shift operations.
The port_timer_set_timeout() and port_timer_set_timeout_random()
functions perform left and right shift operations using the
log_announce_interval and log_sync_interval values as shift counts.
Without bounds validation, these int8_t parameters could be set to
extreme values (e.g., via PTP management messages) that exceed the
valid shift range, causing undefined behavior.
(C11, 6.5.7p3)
> If the value of the right operand is negative or is greater than
or equal to the width of the promoted left operand,
the behavior is undefined
(C++11, 5.8p1)
> The behavior is undefined if the right operand is negative,
or greater than or equal to the length in bits of the promoted
left operand.
Limit both log_announce_interval and log_sync_interval to the range
[-63, 63] using MIN/MAX macros when accepting values from PTP management
frames. This range is preventing shift operations outside
the 64-bit width used in the timeout calculations.
Fixes: GHSA-3v98-458v-388r
Signed-off-by: Adam Wojasinski <awojasinski@baylibre.com>
(cherry picked from commit 5b32348c1b)
dns_unpack_answer() validated only the fixed RR header size and
accepted any rdlength, even one extending past the end of the packet.
TXT and SRV consumers in resolve.c then read up to rdlength bytes from
the message buffer, causing an out-of-bounds read on a truncated or
crafted response.
Reject any RR whose declared rdata extends past dns_msg->msg_size at
the single chokepoint in dns_unpack_answer(), so all current and
future RR consumers are covered.
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 58b46c81c6)
Add a bounds check to prevent a chunk from being written outside the
buffer.
Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit 158df8d088)
The checks validating RA, NS and NA packets content on input were not
correct - packets should be dropped in case any of those checks failed,
however current logic was invalid, causing other checks to be ignored as
long as the ICMPv6 code was correct (i. e. 0).
Apart from fixing the logic, split the single convoluted if condition
into separate if checks for better readability.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 095f064c94)
Add a few new tests covering the bug discovered in ND packet
headers validation on input. Packets with invalid hop limit
should be dropped instead of silently being passed through only
if the ICMPv6 code is correct.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 137d08f879)
Remove the explicit setting of `CONFIG_HEAP_MEM_POOL_SIZE` from NSOS
samples, letting the build system construct the heap size from Kconfig
options.
Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 7e3c5ab2bb)
DNS queries using native posix can return multiple results. Add a
relatively large default to pre-empt failures due to the query being
too successful.
Extra RAM usage can be ignored since NSOS sockets can only exist on
native posix, which has essentially infinite RAM.
Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 3feb7ca425)
The final system heap size is now stored in `K_HEAP_MEM_POOL_SIZE`, not
`CONFIG_HEAP_MEM_POOL_SIZE`.
Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 16c2444d7a)
If CONFIG_HTTP_SERVER_MAX_HEADER_LEN is increased from the default of
32, a compiler warning pops in the HTTP websocket code:
zephyr/subsys/net/lib/http/http_server_http1.c:
In function 'on_header_value':
zephyr/subsys/net/lib/http/http_server_http1.c:898:33:
warning: 'strncpy' output may be truncated copying between 0 and 32
bytes from a string of length 47 [-Wstringop-truncation]
898 | strncpy(ctx->ws_sec_key, ctx->header_buffer,
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
899 | MIN(sizeof(ctx->ws_sec_key), offset));
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
This comes from:
if (ctx->websocket_sec_key_next) {
#if defined(CONFIG_WEBSOCKET)
strncpy(ctx->ws_sec_key, ctx->header_buffer,
MIN(sizeof(ctx->ws_sec_key), offset));
#endif
If eg. header_buffer is 48 bytes and holds a string >= 32 bytes then
ws_sec_key can end up non-nul terminated. That can then lead to buffer
overflow in handle_http1_to_websocket_upgrade().
Add a check to make sure the header value fits in ws_sec_key, if not
reject the request with a HTTP 500. The websocket key is not expected to
be > 31 bytes.
Once the check is in place, it's safe to use memcpy() for the copy, and
then add the terminating nul manually.
Signed-off-by: Michael Ellerman <mpe@oss.tenstorrent.com>
(cherry picked from commit 5d653fcfd4)
With PR #107089 the conf file 'cc3220sf_launchxl.conf' in the WiFi Shell
sample was renamed to 'cc3220sf_launchxl_cc3220sf.conf'.
Signed-off-by: Stephan Linz <linz@li-pro.net>
Resuming the device involves hardware accesses including register
writes, so we need to acquire the semaphore lock first to avoid
interference with other cores also using the RNG.
Signed-off-by: Sarah Renkhoff <sarah.renkhoff@gmail.com>
(cherry picked from commit 95ff84434f)
Modify driver to process interrupts from upper half ISR then signal a
bottom half ISR thread which performs callback invokation. This ensures
callbacks run in thread context which is necessary for proper operation of
various classes.
Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 9ec2cd318f)
The commit c42c8a4da4 (do not invalidate bet at end of loop")
correctly restored the best erase type (bet) selection logic
based on SFDP/JESD216 erase types.
However, this caused a regression
in Octal OPI mode: when bet != NULL, the driver started using bet->cmd
(a standard SPI 1-byte opcode) directly, which is not valid in OPI mode
where the controller expects OPI opcodes (2-byte OCMD).
When bet != NULL:
- In OPI mode, ignore bet->cmd and use the OPI sector erase
opcode SPI_NOR_OCMD_SE.
- In SPI/QPI modes, keep using bet->cmd as intended.
Signed-off-by: Fabrice DJIATSA <fabrice.djiatsa-ext@st.com>
(cherry picked from commit 955f376078)
This modification prevents the bet pointer from being nulled at the end
of the loop, which would otherwise render the search for a suitable
erase type ineffective. It also optimize the loop as it omits
unnecessary operations.
Without this change, the erase size defaults to one sector. If the chip
defines fewer than JESD216_NUM_ERASE_TYPES (=4) erase types, this
behavior still works, as the resulting command will correspond to a
sector erase operation. However, if the chip defines all erase types,
the resulting command will be the one specified in the erase type. But
since bet is nulled, the erase size will incorrectly default to the
sector size.
Signed-off-by: Martin Gysel <me@bearsh.org>
(cherry picked from commit c42c8a4da4)
Fix a scenario where the logging thread can enter an infinite
loop and starve lower-priority threads when encountering an
uncommitted log message.
If a lower-priority thread is preempted before committing a
message, and a higher-priority thread triggers log processing,
the logging thread may repeatedly attempt to claim it. Since the
message is pending but not committed, z_log_msg_claim() returns
NULL while z_log_msg_pending() remains true, resulting in a
livelock.
Update the log processing logic to avoid looping on uncommitted
messages, allowing lower-priority threads to resume and complete
the commit.
Fixes#101401
Signed-off-by: Javier Romera <lromerajdev@gmail.com>
(cherry picked from commit 5184eac621)
When logging statically configured network SSID, use the Kconfig string
instead of a SSID buffer where it was copied to, as the latter is not
guarantee to be NULL terminated.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 4f09d6bcbc)
In case CONFIG_WIFI_CREDENTIALS_STATIC is used, verify the statically
configured SSID/password lengths to guarantee they don't exceed the
allowed SSID and password character limits and thus overflow credential
buffers.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 90d9d8e12d)
net_tcp_foreach() drops tcp_lock before the callback and re-acquires
it afterwards. A concurrent tcp_conn_release() can free the next
node cached by SYS_SLIST_FOR_EACH_CONTAINER_SAFE during this window,
causing the iterator to follow a dangling pointer on the next
iteration.
Move context teardown in tcp_conn_release() inside the tcp_lock
critical section and keep tcp_lock held across the callback in
net_tcp_foreach(). No current callback acquires tcp_lock.
Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
(cherry picked from commit cd85e0e890)
Fixes an issue whereby a write might have partially been successful
but failed due to insufficient space in the storage device by
re-attempting the write again with the offset, and if it still
fails, return an error
Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit f99dbd622e)
Make sure to check packet length check before starting the
IPv4 fragmentation reassembly process. This way we can drop the
malformed packet without consuming resources.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 0747bca9e1)
In a few series managed by the common driver, the LSEDRV field is not in
RCC_BDCR but a different register.
Use proper register name when obtaining the shift to ensure a non-zero
driving capability can be used on these series.
Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 0f6b8c19ab)
ISR bits are set on input level or edge changes, regardless of whether an
interrupt is actually enabled on that line. Therefore, we check whether an
interrupt is actually enabled by masking with IMR. If we didn't do this,
some other enabled interrupt firing could also result in a callback for a
disabled interrupt.
Signed-off-by: Bert Abrath <bert.abrath@basalte.be>
(cherry picked from commit fe0ad472cd)
Fixes build when OPENTHREAD_CONFIG_DIAG_ENABLE is enabled due to
removed callbacks.
Signed-off-by: Bas van Loon <bas@arch-embedded.com>
(cherry picked from commit 83597841ff)
When calling zsock_recvmsg()/zsock_sendmsg() system calls, check if
provided msg->msg_iovlen is valid, i.e. does not cause size_t overflow
when calculating memory needed for msg->msg_iov vector.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit b9ad6b17c7)
When comparing time sources for `CONFIG_SNTP_UNCERTAINTY` to validate
the server responses, `dest_ts_us` and `orig_ts_us` need to be
constructed from the same time sources and have the same offsets applied
in order for math operations to be valid.
Fixes#105101
Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 4a2374c7a1)
Add interrupt locking to arc_core_mpu_buffer_validate() to be atomic.
The function iterates through MPU regions using bank selection, which
requires multiple register accesses. Without interrupt protection, an
interrupt or context switch during iteration can corrupt the bank
selection state, causing incorrect region lookups and spurious access
denials.
Signed-off-by: Mohamed Moawad <moawad@synopsys.com>
(cherry picked from commit c0304cb3ba)
Don't allow the LPTIM system clock driver to be enabled if the required
nodelabel `stm32_lp_tick_source` does not exist. This prevents incorrect
usage which could result in non-trivial build failures.
Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 94574740f2)
The `stm32_lp_tick_source` nodelabel must be placed on a low-power timer to
use it as system clock timer. This was not done by this board so the
Kconfig was unable to determine which clock source was used, and ultimately
resulting in a build error because option `STM32_LPTIM_TIMEBASE` had no
value.
Fix by adding the missing nodelabel.
Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 75fdc2f848)
Prevent writing data that is larger than the destination struct's size.
Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
(cherry picked from commit bcc4c0bb1e)
Error codes of group 'stat' were incorrectly labeled as group 'zbasic'.
Signed-off-by: Martin Stumpf <finomnis@gmail.com>
(cherry picked from commit 2ef7ee567e)