Skip to content

fix: prevent buffer overflow in I-Am-Router-To-Network message - #1438

Merged
skarg merged 2 commits into
masterfrom
bugfix/i-am-router-to-network-buffer-overflow
Jul 27, 2026
Merged

fix: prevent buffer overflow in I-Am-Router-To-Network message#1438
skarg merged 2 commits into
masterfrom
bugfix/i-am-router-to-network-buffer-overflow

Conversation

@skarg

@skarg skarg commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the demo router applications’ encoding of the I-Am-Router-To-Network network-layer message by adding bounds checks to prevent writing past Tx_Buffer when enumerating reachable networks.

Changes:

  • Added pre-encode capacity checks before appending 16-bit network numbers to Tx_Buffer.
  • Emit a warning log and truncate the network list when the transmit buffer is full.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
apps/router-mstp/main.c Adds Tx_Buffer bounds checks while encoding I-Am-Router-To-Network network lists.
apps/router-ipv6/main.c Mirrors the same overflow-prevention checks for the IPv6 router app.

Comment thread apps/router-mstp/main.c
Comment thread apps/router-ipv6/main.c
…oop exits while the buffer is full to avoid duplicate warnings and extra iteration.ing in example router app.
@skarg
skarg merged commit 90ef0bc into master Jul 27, 2026
36 checks passed
@skarg
skarg deleted the bugfix/i-am-router-to-network-buffer-overflow branch July 27, 2026 19:10
skarg added a commit that referenced this pull request Aug 4, 2026
* doc: add CVE-2026-64675 to GHSA-mmg6-p4pr-cj6h advisory entry

The published advisory for GHSA-mmg6-p4pr-cj6h (pre-auth OOB read in
xy_color_decode) was assigned CVE-2026-64675, but the SECURITY.md
entry was missing the CVE link. Add it to match the published record.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* doc: add 9 draft advisory entries to SECURITY.md

Add entries for all draft GHSA advisories visible after authentication:

- GHSA-f23j-5f4w-cxhj: Command object action list resize heap use-after-free write (1.7.0-rc2, PR #1461)
- GHSA-rxvq-3mhq-474x: Cross-peer disclosure caused by a BVLC length mismatch (1.4.6/1.5.2/1.6.1/1.7.0, PR #1451)
- GHSA-9qx8-hr5x-r35c: Silent decode failure in bacnet_octet_string_decode() (1.4.6/1.5.2/1.6.1/1.7.0, PR #1440)
- GHSA-gv7j-28x8-cr37: AtomicWriteFile access-method mismatch leading to RAMFS heap OOB read (1.4.6/1.5.2/1.6.1/1.7.0, PR #1439)
- GHSA-gj7v-fwjp-7x8q: Router route-table Tx_Buffer overflow (1.4.6/1.5.2/1.6.1/1.7.0, PR #1438)
- GHSA-hg85-pmm3-jfcf: Structured View subordinate-list[0] unbounded resize DoS (1.6.1/1.7.0, PR #1437)
- GHSA-92q2-p4vr-fvmp: BACnet/SC hub never requires a client cert (1.4.6/1.5.2/1.6.1/1.7.0, PR #1436)
- GHSA-gr74-333w-7wg8: Trailing MORE bit BACnet/SC header option OOB read/write (1.4.6/1.5.2/1.6.1/1.7.0, PR #1435)
- GHSA-jgm4-2wg9-jwfg: BACnet/SC node accepts self-signed hub cert MITM (1.4.6/1.5.2/1.6.1/1.7.0, PR #1434)

None of these drafts have CVE IDs assigned yet.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
skarg added a commit that referenced this pull request Aug 11, 2026
skarg added a commit that referenced this pull request Aug 11, 2026
skarg added a commit that referenced this pull request Aug 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants