diff mbox series

[3/4] Fix CVE-2024-7547

Message ID 20241203194352.25514-3-ivo.g.dimitrov.75@gmail.com (mailing list archive)
State Accepted
Commit 305df050d02aea8532f7625d6642685aa530f9b0
Headers show
Series [1/4] stkutil: Fix CVE-2024-7544 | expand

Commit Message

Ivaylo Dimitrov Dec. 3, 2024, 7:43 p.m. UTC
---
 src/smsutil.c | 3 +++
 1 file changed, 3 insertions(+)
diff mbox series

Patch

diff --git a/src/smsutil.c b/src/smsutil.c
index 8f578c22..484bfd0b 100644
--- a/src/smsutil.c
+++ b/src/smsutil.c
@@ -1464,6 +1464,9 @@  static gboolean decode_command(const unsigned char *pdu, int len,
 	if ((len - offset) < out->command.cdl)
 		return FALSE;
 
+	if (out->command.cdl > sizeof(out->command.cd))
+		return FALSE;
+
 	memcpy(out->command.cd, pdu + offset, out->command.cdl);
 
 	return TRUE;