Received: by 2002:a25:23cc:0:0:0:0:0 with SMTP id j195csp1093643ybj; Thu, 7 May 2020 14:48:22 -0700 (PDT) X-Google-Smtp-Source: APiQypJloxlg8RSouKUQuV2qIDESgd3iZd/b9o9uTiDN21u5gSfXNMIMJjX9/n1KUpsEDTtRcOZ4 X-Received: by 2002:a17:906:168f:: with SMTP id s15mr14534516ejd.17.1588888102436; Thu, 07 May 2020 14:48:22 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1588888102; cv=none; d=google.com; s=arc-20160816; b=TdMzVw/4lNMuYz50vIOu1mmgdlCZB1IAtZRYCBt3Y67A/nVqRfj3exNrGH7coTmu9Y zGO+f4ArzGKdnHm0/Vl0OtQE1mnLiUi8LXedbZqGF42DCelsN5fUcwbaONhryCovmS1U OyEjgmGtVcMRjvv7z84qzGUEYUP+GCqd8T/B6J4Cf4CdgcDefGo+Aa6R7HstyAQ6mR0E Jz9xMlPlAHTYS1wL4G3udf89KLhUDUhFEhCVLezgY/g4sbVv4HzDeAbgb5d6d1cF4diu nEvgdbhr/wDv2SLFIpZ71nnJE2BCeQkE8e4lRLDepXQjnMHciVIiahMxJVL1H70yRTI7 OiEw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=RvROpc/zpTt4iCs8QLoqDIqfRFxTZYoIMA8VR31sM6U=; b=1GqxVDuOspnGBtTUYtVzINnJTMRJbEchTfgDjz1m+fuhjd7wpcuL8QSxZ8TJv1x2PY /Sp+lwvnT/UiP/8xBBfKh0ugeaKD6W2iufDyx2E1oa+V1D3fLxpqF3uZocuqvsS3taUF wW6jDg+fjPQ6rz1zln8kF68+Ya/lBfgJ0qIRhaMQxJNiLTOgeCt8WeTXS6yTM235FDKq cq/saNqTT9p4KgfPeyn/ehzH/14sqmtYufvMRid2cH8XhO3B9QK0zVy++UJuhZkc3p7C XlYIW6Hfi4aNZu83nH1cDp3gU4yu0LviTVJw0qPBgOt8kfu6Hc6ne5/V/UkahlrohUA2 CgzA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@codecoup-pl.20150623.gappssmtp.com header.s=20150623 header.b=K8vEbtti; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id f16si1613631edr.583.2020.05.07.14.47.44; Thu, 07 May 2020 14:48:22 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@codecoup-pl.20150623.gappssmtp.com header.s=20150623 header.b=K8vEbtti; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726445AbgEGVpr (ORCPT + 99 others); Thu, 7 May 2020 17:45:47 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60866 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726437AbgEGVpr (ORCPT ); Thu, 7 May 2020 17:45:47 -0400 Received: from mail-lj1-x234.google.com (mail-lj1-x234.google.com [IPv6:2a00:1450:4864:20::234]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 54A45C05BD43 for ; Thu, 7 May 2020 14:45:47 -0700 (PDT) Received: by mail-lj1-x234.google.com with SMTP id a21so7960195ljj.11 for ; Thu, 07 May 2020 14:45:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=codecoup-pl.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=RvROpc/zpTt4iCs8QLoqDIqfRFxTZYoIMA8VR31sM6U=; b=K8vEbttiEGHaLh0+BzNeX+yKmej0ZLRuGczZZJSQe6SLk7pkRrlOTs6/cffBiZbcpv v0DSCGJi9IN829iyLfpA91sdAwMr3KT+Xa5zAzMNeuQC2dXbbnc0aqbasYNf7LCVJINa KuHTEtORxRBi3Fn7GWW6mDLENorVEOd2Y8X6z1PYgJi/EcG5CGxrsH4idgYr6Th2Er8d je8GJlXOP3UtSGXc+3SoPIfmy7s8+0Mk4KVqgerPdB6m6gNihmGy0E5+IM9ae+IkDI2q aTDkzm31tisJDiiyfa5bLLJihQrU/q1X5KA2wfV3EZYCkUqkiUqW5SuwCasqtVVTKLPR P7OQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=RvROpc/zpTt4iCs8QLoqDIqfRFxTZYoIMA8VR31sM6U=; b=H32ZmsucgO0Sr7W6WeV2mIKWz3rxQ3z6V5nGOQ2q/52bnLMny7mluYjeSaEM+J9uX6 stfm+s35bZUm9v+LvWWpaQQFkHzeTZ1k4tkYDAlYS6n2+Nyf5roYNQtgWigSbBhpSp85 sFCk6E2HJuBbSyxS42UOTgjNR7OKrL0xi/V71ncU4VhrGxHseMc2T74GRohPW3Lcqd9Q lWMMt9SaBIbPUtmBavYOlB8aDrQqv04Y6kqafwiDqcgc1oXUh3x00xHL4STwKVky6EVA sue1IbIVj2Dw+Mhzt0XU3Ju5Pyet3on5dRfLn6FnyG/KQqYf79OsmiFL+bEgTFAra8JL cNXg== X-Gm-Message-State: AGi0PuZXP/qVV/dMO227xaZ1qB1lSgq94MtNMO8q7nvD4dvJXKyoCzQm mEL2Qqix9VAuDLEQlsUoU4MrJTiqWbY= X-Received: by 2002:a2e:80d2:: with SMTP id r18mr9518674ljg.269.1588887945446; Thu, 07 May 2020 14:45:45 -0700 (PDT) Received: from rymek.homerouter.cpe (apn-77-115-197-29.dynamic.gprs.plus.pl. [77.115.197.29]) by smtp.gmail.com with ESMTPSA id s27sm3974972ljo.80.2020.05.07.14.45.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 07 May 2020 14:45:44 -0700 (PDT) From: =?UTF-8?q?=C5=81ukasz=20Rymanowski?= To: linux-bluetooth@vger.kernel.org Cc: =?UTF-8?q?=C5=81ukasz=20Rymanowski?= Subject: [PATCH BlueZ] client: Fix possible stack corruption Date: Thu, 7 May 2020 23:45:37 +0200 Message-Id: <20200507214537.4504-1-lukasz.rymanowski@codecoup.pl> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-bluetooth-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org DBUS_TYPE_BOOLEAN is 'int', which does not have to be the same size as 'bool'. On architecture where bool is smaller than in, getting prepare-authorize will corrupt the stack --- client/gatt.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/client/gatt.c b/client/gatt.c index 416eda953..9d35b54fa 100644 --- a/client/gatt.c +++ b/client/gatt.c @@ -1860,9 +1860,12 @@ static int parse_options(DBusMessageIter *iter, uint16_t *offset, uint16_t *mtu, } else if (strcasecmp(key, "prepare-authorize") == 0) { if (var != DBUS_TYPE_BOOLEAN) return -EINVAL; - if (prep_authorize) - dbus_message_iter_get_basic(&value, - prep_authorize); + if (prep_authorize) { + int tmp; + + dbus_message_iter_get_basic(&value, &tmp); + *prep_authorize = !!tmp; + } } dbus_message_iter_next(&dict); -- 2.20.1