mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-09-29 02:10:52 +00:00
CVE-2024-45616: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card. Reference: [https://nvd.nist.gov/vuln/detail/CVE-2024-45616] Upstream patches: [1d3b410e06] [265b28344d] [e7177c7ca0] [ef7b10a18e] [76115e3479] [16ada9dc7c] [3562969c90] [cccdfc46b1] [5fa758767e] [aa102cd9ab] Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
34 lines
1.3 KiB
Diff
34 lines
1.3 KiB
Diff
From aa102cd9abe1b0eaf537d9dd926844a46060d8bc Mon Sep 17 00:00:00 2001
|
|
From: =?UTF-8?q?Veronika=20Hanul=C3=ADkov=C3=A1?= <vhanulik@redhat.com>
|
|
Date: Tue, 23 Jul 2024 10:48:32 +0200
|
|
Subject: [PATCH] card-entersafe: Check length of serial number
|
|
|
|
Thanks Matteo Marini for report
|
|
https://github.com/OpenSC/OpenSC/security/advisories/GHSA-p3mx-7472-h3j8
|
|
|
|
fuzz_pkcs15_reader/5
|
|
|
|
CVE: CVE-2024-45616
|
|
Upstream-Status: Backport [https://github.com/OpenSC/OpenSC/commit/aa102cd9abe1b0eaf537d9dd926844a46060d8bc]
|
|
|
|
Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
|
|
---
|
|
src/libopensc/card-entersafe.c | 2 ++
|
|
1 file changed, 2 insertions(+)
|
|
|
|
diff --git a/src/libopensc/card-entersafe.c b/src/libopensc/card-entersafe.c
|
|
index 6372913d0..305323fd5 100644
|
|
--- a/src/libopensc/card-entersafe.c
|
|
+++ b/src/libopensc/card-entersafe.c
|
|
@@ -1468,6 +1468,8 @@ static int entersafe_get_serialnr(sc_card_t *card, sc_serial_number_t *serial)
|
|
r=entersafe_transmit_apdu(card, &apdu,0,0,0,0);
|
|
LOG_TEST_RET(card->ctx, r, "APDU transmit failed");
|
|
LOG_TEST_RET(card->ctx, sc_check_sw(card,apdu.sw1,apdu.sw2),"EnterSafe get SN failed");
|
|
+ if (apdu.resplen != 8)
|
|
+ LOG_TEST_RET(card->ctx, SC_ERROR_UNKNOWN_DATA_RECEIVED, "Invalid length of SN");
|
|
|
|
card->serialnr.len=serial->len=8;
|
|
memcpy(card->serialnr.value,rbuf,8);
|
|
--
|
|
2.34.1
|