mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-10-02 14:04:47 +00:00
Backport fixes for : * CVE-2024-8645 - Upstream-Status: Backport from8e5f8de883* CVE-2026-0960 - Upstream-Status: Backport fromf31123dcdb* CVE-2025-13945 - Upstream-Status: Backport from9139917bd8Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
89 lines
3.5 KiB
Diff
89 lines
3.5 KiB
Diff
From 15c4d1f9078b484cb95ef645a7d4dc68212849f7 Mon Sep 17 00:00:00 2001
|
|
From: John Thacker <johnthacker@gmail.com>
|
|
Date: Wed, 29 May 2024 14:23:04 +0000
|
|
Subject: SPRT: Fix crash
|
|
|
|
SDP can setup a RTP conversation with a setup frame before the current
|
|
frame, which changes the dissection on the second pass. If in the period
|
|
in the middle there is a SPRT packet, it can be dissected differently on
|
|
the second pass, and the SPRT conversation data won't be found on the
|
|
second pass.
|
|
|
|
Fix #19559 (at least prevent the crash. There's some more cleanup that
|
|
should happen.)
|
|
|
|
(cherry picked from commit 05f6364cbd766e8758f98c5ee2070aef27c1ffef)
|
|
|
|
CVE: CVE-2024-8645
|
|
Upstream-Status: Backport [https://gitlab.com/wireshark/wireshark/-/commit/8e5f8de8836d3a81276ae5b9bf78cbac58bb6108]
|
|
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
|
|
---
|
|
epan/dissectors/packet-rtp.c | 3 +++
|
|
epan/dissectors/packet-sprt.c | 29 +++++++++++++++++------------
|
|
2 files changed, 20 insertions(+), 12 deletions(-)
|
|
|
|
diff --git a/epan/dissectors/packet-rtp.c b/epan/dissectors/packet-rtp.c
|
|
index e96d994..ed4a78a 100644
|
|
--- a/epan/dissectors/packet-rtp.c
|
|
+++ b/epan/dissectors/packet-rtp.c
|
|
@@ -1092,6 +1092,9 @@ srtp_add_address(packet_info *pinfo, const port_type ptype, address *addr, int p
|
|
* If not, create a new conversation.
|
|
*/
|
|
if (!p_conv || p_conv->setup_frame != setup_frame_number) {
|
|
+ /* XXX - If setup_frame_number < pinfo->num, creating this conversation
|
|
+ * can mean that the dissection is different on later passes.
|
|
+ */
|
|
p_conv = conversation_new(setup_frame_number, addr, &null_addr, conversation_pt_to_endpoint_type(ptype),
|
|
(guint32)port, (guint32)other_port,
|
|
NO_ADDR2 | (!other_port ? NO_PORT2 : 0));
|
|
diff --git a/epan/dissectors/packet-sprt.c b/epan/dissectors/packet-sprt.c
|
|
index 17bf329..726cbf0 100644
|
|
--- a/epan/dissectors/packet-sprt.c
|
|
+++ b/epan/dissectors/packet-sprt.c
|
|
@@ -1341,6 +1341,23 @@ dissect_sprt(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_
|
|
/*guint16 tcn;*/
|
|
/*guint16 sqn;*/
|
|
|
|
+ /* Get conversation data, or create it if not found */
|
|
+ p_conv_data = find_sprt_conversation_data(pinfo);
|
|
+ if (!p_conv_data)
|
|
+ {
|
|
+ sprt_add_address(pinfo,
|
|
+ &pinfo->src, pinfo->srcport,
|
|
+ 0,
|
|
+ "SPRT stream",
|
|
+ pinfo->num);
|
|
+ p_conv_data = find_sprt_conversation_data(pinfo);
|
|
+ if (!p_conv_data) {
|
|
+ // This shouldn't happen; likely a new RTP conversation was set up
|
|
+ // after this frame but with a setup frame before this one.
|
|
+ return 0;
|
|
+ }
|
|
+ }
|
|
+
|
|
/* Make entries in Protocol column and Info column on summary display */
|
|
col_set_str(pinfo->cinfo, COL_PROTOCOL, "SPRT");
|
|
col_clear(pinfo->cinfo, COL_INFO);
|
|
@@ -1395,18 +1412,6 @@ dissect_sprt(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_
|
|
|
|
noa = (tvb_get_ntohs(tvb, offset + 4) & 0xC000) >> 14;
|
|
|
|
- /* Get conversation data, or create it if not found */
|
|
- p_conv_data = find_sprt_conversation_data(pinfo);
|
|
- if (!p_conv_data)
|
|
- {
|
|
- sprt_add_address(pinfo,
|
|
- &pinfo->src, pinfo->srcport,
|
|
- 0,
|
|
- "SPRT stream",
|
|
- pinfo->num);
|
|
- p_conv_data = find_sprt_conversation_data(pinfo);
|
|
- }
|
|
-
|
|
proto_tree_add_item(sprt_tree, hf_sprt_header_extension_bit, tvb, offset, 1, ENC_BIG_ENDIAN);
|
|
proto_tree_add_item(sprt_tree, hf_sprt_subsession_id, tvb, offset, 1, ENC_BIG_ENDIAN);
|
|
offset++;
|
|
--
|
|
2.50.1
|
|
|