]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core-contrib.git/commitdiff
ofono: patch CVE-2024-7540, CVE-2024-7541, CVE-2024-7542
authorPeter Marko <peter.marko@siemens.com>
Sun, 19 Jan 2025 16:34:38 +0000 (17:34 +0100)
committerRoss Burton <ross.burton@arm.com>
Thu, 23 Jan 2025 12:03:45 +0000 (12:03 +0000)
Cherry-pick commit
https://git.kernel.org/pub/scm/network/ofono/ofono.git/commit/?id=29ff6334b492504ace101be748b256e6953d2c2f

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Ross Burton <ross.burton@arm.com>
meta/recipes-connectivity/ofono/ofono/CVE-2024-7540_CVE-2024-7541_CVE-2024-7542.patch [new file with mode: 0644]
meta/recipes-connectivity/ofono/ofono_2.14.bb

diff --git a/meta/recipes-connectivity/ofono/ofono/CVE-2024-7540_CVE-2024-7541_CVE-2024-7542.patch b/meta/recipes-connectivity/ofono/ofono/CVE-2024-7540_CVE-2024-7541_CVE-2024-7542.patch
new file mode 100644 (file)
index 0000000..fd97d4b
--- /dev/null
@@ -0,0 +1,52 @@
+From 29ff6334b492504ace101be748b256e6953d2c2f Mon Sep 17 00:00:00 2001
+From: "Sicelo A. Mhlongo" <absicsz@gmail.com>
+Date: Tue, 17 Dec 2024 11:31:28 +0200
+Subject: [PATCH] atmodem: sms: ensure buffer is initialized before use
+
+Fixes: CVE-2024-7540
+Fixes: CVE-2024-7541
+Fixes: CVE-2024-7542
+
+CVE: CVE-2024-7540
+CVE: CVE-2024-7541
+CVE: CVE-2024-7542
+Upstream-Status: Backport [https://git.kernel.org/pub/scm/network/ofono/ofono.git/commit/?id=29ff6334b492504ace101be748b256e6953d2c2f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ drivers/atmodem/sms.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/drivers/atmodem/sms.c b/drivers/atmodem/sms.c
+index d994856b..0668c631 100644
+--- a/drivers/atmodem/sms.c
++++ b/drivers/atmodem/sms.c
+@@ -399,7 +399,7 @@ static void at_cmt_notify(GAtResult *result, gpointer user_data)
+       struct sms_data *data = ofono_sms_get_data(sms);
+       GAtResultIter iter;
+       const char *hexpdu;
+-      unsigned char pdu[176];
++      unsigned char pdu[176] = {0};
+       long pdu_len;
+       int tpdu_len;
+@@ -466,7 +466,7 @@ static void at_cmgr_notify(GAtResult *result, gpointer user_data)
+       struct sms_data *data = ofono_sms_get_data(sms);
+       GAtResultIter iter;
+       const char *hexpdu;
+-      unsigned char pdu[176];
++      unsigned char pdu[176] = {0};
+       long pdu_len;
+       int tpdu_len;
+@@ -648,7 +648,7 @@ static void at_cmgl_notify(GAtResult *result, gpointer user_data)
+       struct sms_data *data = ofono_sms_get_data(sms);
+       GAtResultIter iter;
+       const char *hexpdu;
+-      unsigned char pdu[176];
++      unsigned char pdu[176] = {0};
+       long pdu_len;
+       int tpdu_len;
+       int index;
+-- 
+2.30.2
+
index 34e919ef5ac3f941aa65e8e6c874dc0762caa343..9a91afaa7be9de1a873cb2517979b5772141b3b3 100644 (file)
@@ -12,6 +12,7 @@ SRC_URI = "\
     file://rmnet.patch \
     file://ofono \
     file://CVE-2024-7539.patch \
+    file://CVE-2024-7540_CVE-2024-7541_CVE-2024-7542.patch \
 "
 SRC_URI[sha256sum] = "983cbfd5e1e1a410ba7ad2db7f50fadc91e50b29f1ede40cdc73f941da7ba95f"