Conversation
1. Potential stack/heap overflow from unchecked RF24 frame size 2. Unchecked payload length when packing UDP buffer 3. Out-of-bounds reads during packet parsing (short packet not checked)
2bndy5
left a comment
There was a problem hiding this comment.
I'm assuming the 6 and 20 are thresholds required to prevent UB. At least the other added bounds checking uses an explanatory const name (MAX_PAYLOAD_SIZE).
|
Yes, the >6 & >20 thresholds would leave us with a 1-byte payload. |
|
Can we add a comment or replace the magic numbers with a named const? I have no problem with the added conditional checks, but I'd like to leave some kind of breadcrumb that doesn't require |
Yes. Do you have a preference? Feel free to modify. |
|
I think a comment would good enough, but I'm not familiar with the context by just looking at the diff. Did the AGENTS.md help AI in analyzing the RF24 stack for this? I've never used AI for C++. |
I'm not sure, I just asked it to find buffer overflows and memory leaks in RF24Gateway, and pointed it at the gateway repo. Then I asked it to validate my fixes in this branch. |
|
Is this good? |
|
Perfect. better than I expected. Looking at your session here, I don't think it needed to deep dive into the stack. |
- Add comments to latest fixes - Modify the return call to continue in the first fix
Probably not, but it can't hurt to verify things down the stack. As you can see there are still a couple remaining issues to address, but the fixes here are the main areas of possible external exploits. |
Fixes for RF24Gatway w/help from AI:
Potential stack/heap overflow from unchecked RF24 frame size
File: /tmp/workspace/nRF24/RF24Gateway/RF24Gateway.cpp
Function: ESBGateway::handleRadioIn
Location: line 400 (memcpy(&msg.message, &f.message_buffer, f.message_size);)
Why dangerous: msg.message is fixed-size (MAX_PAYLOAD_SIZE in header), but f.message_size is not bounded before copy.
Risk: If f.message_size > MAX_PAYLOAD_SIZE, this overflows msg.message. Potentially exploitable if attacker can inject malformed/corrupted radio frames.
Unchecked payload length when packing UDP buffer
File: /tmp/workspace/nRF24/RF24Gateway/RF24Gateway.cpp
Function: ESBGateway::sendUDP
Location: lines 759–766 (uint8_t buffer[MAX_PAYLOAD_SIZE + 11]; ... memcpy(... frame.message_size);)
Why dangerous: Copies frame.message_size bytes into fixed stack buffer without validating frame.message_size <= MAX_PAYLOAD_SIZE.
Risk: Stack overflow if oversized frame reaches this function. Could be exploitable depending on call path/input control.
Out-of-bounds reads during packet parsing (short packet not checked)
File: /tmp/workspace/nRF24/RF24Gateway/RF24Gateway.cpp
Function: ESBGateway::handleRadioOut
Location: lines 508–509, 554, 561 (tmp+4, tmp[19], tmp[16])
Why dangerous: Code reads specific offsets from msgTx->message before verifying minimum packet length.
Risk: OOB read/crash with truncated packets from TUN/TAP input. Mostly robustness/DoS, but parser bugs are security-relevant.