Skip to content

fix: add size limits for remotely writable BACnet array or list elements - #1437

Merged
skarg merged 4 commits into
masterfrom
bugfix/unbounded-remote-resizable-bacnet-array-lists
Jul 27, 2026
Merged

fix: add size limits for remotely writable BACnet array or list elements#1437
skarg merged 4 commits into
masterfrom
bugfix/unbounded-remote-resizable-bacnet-array-lists

Conversation

@skarg

@skarg skarg commented Jul 23, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds configurable upper bounds on remotely writable BACnetARRAY/BACnetLIST growth to prevent a single WriteProperty request from triggering large synchronous expansion/processing loops in object write paths.

Changes:

  • Add compile-time size caps (default 1024) for Structured View Subordinate_List and Command Action_List array resizing.
  • Add compile-time size cap (default 1024) for Life Safety Zone Zone_Members list writes, rejecting oversized payloads with ERROR_CODE_VALUE_OUT_OF_RANGE.
  • Apply the new bounds during resize/write operations to short-circuit potentially expensive loops.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
src/bacnet/basic/object/structured_view.c Adds a configurable maximum for Subordinate_List resizing and rejects oversized array-size writes.
src/bacnet/basic/object/lsz.c Adds a configurable maximum for Zone_Members list size during writes (and currently also in the exported Add helper).
src/bacnet/basic/object/command.c Adds a configurable maximum for Action_List resizing and rejects oversized array-size writes.

Comment thread src/bacnet/basic/object/lsz.c Outdated
skarg and others added 3 commits July 23, 2026 22:10
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@skarg
skarg merged commit c52be33 into master Jul 27, 2026
36 checks passed
@skarg
skarg deleted the bugfix/unbounded-remote-resizable-bacnet-array-lists branch July 27, 2026 13:13
skarg added a commit that referenced this pull request Aug 4, 2026
* doc: add CVE-2026-64675 to GHSA-mmg6-p4pr-cj6h advisory entry

The published advisory for GHSA-mmg6-p4pr-cj6h (pre-auth OOB read in
xy_color_decode) was assigned CVE-2026-64675, but the SECURITY.md
entry was missing the CVE link. Add it to match the published record.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* doc: add 9 draft advisory entries to SECURITY.md

Add entries for all draft GHSA advisories visible after authentication:

- GHSA-f23j-5f4w-cxhj: Command object action list resize heap use-after-free write (1.7.0-rc2, PR #1461)
- GHSA-rxvq-3mhq-474x: Cross-peer disclosure caused by a BVLC length mismatch (1.4.6/1.5.2/1.6.1/1.7.0, PR #1451)
- GHSA-9qx8-hr5x-r35c: Silent decode failure in bacnet_octet_string_decode() (1.4.6/1.5.2/1.6.1/1.7.0, PR #1440)
- GHSA-gv7j-28x8-cr37: AtomicWriteFile access-method mismatch leading to RAMFS heap OOB read (1.4.6/1.5.2/1.6.1/1.7.0, PR #1439)
- GHSA-gj7v-fwjp-7x8q: Router route-table Tx_Buffer overflow (1.4.6/1.5.2/1.6.1/1.7.0, PR #1438)
- GHSA-hg85-pmm3-jfcf: Structured View subordinate-list[0] unbounded resize DoS (1.6.1/1.7.0, PR #1437)
- GHSA-92q2-p4vr-fvmp: BACnet/SC hub never requires a client cert (1.4.6/1.5.2/1.6.1/1.7.0, PR #1436)
- GHSA-gr74-333w-7wg8: Trailing MORE bit BACnet/SC header option OOB read/write (1.4.6/1.5.2/1.6.1/1.7.0, PR #1435)
- GHSA-jgm4-2wg9-jwfg: BACnet/SC node accepts self-signed hub cert MITM (1.4.6/1.5.2/1.6.1/1.7.0, PR #1434)

None of these drafts have CVE IDs assigned yet.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants