From dafff9fb60281817225f1ce6371a5aa2fbb967a4 Mon Sep 17 00:00:00 2001 From: Roberto Paleari Date: Wed, 29 Apr 2026 14:18:31 +0200 Subject: [PATCH] res/res_pjsip_pubsub.c: Fix buffer over-read in MWI body parser Add constraint checks to prevent unauthenticated users from crashing Asterisk instance by sending a crafted inbound SIP NOTIFY request with "Content-Type: application/simple-message-summary". Resolves: #GHSA-8jw3-ccr9-xrmf --- res/res_pjsip_pubsub.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/res/res_pjsip_pubsub.c b/res/res_pjsip_pubsub.c index 1aa38e0332..ac927d1424 100644 --- a/res/res_pjsip_pubsub.c +++ b/res/res_pjsip_pubsub.c @@ -3894,6 +3894,7 @@ static pj_bool_t pubsub_on_rx_mwi_notify_request(pjsip_rx_data *rdata) char *context; char *body; char *mailbox; + int body_len; int rc; endpoint = ast_pjsip_rdata_get_endpoint(rdata); @@ -3926,9 +3927,16 @@ static pj_bool_t pubsub_on_rx_mwi_notify_request(pjsip_rx_data *rdata) context = atsign + 1; body = ast_alloca(rdata->msg_info.msg->body->len + 1); - rdata->msg_info.msg->body->print_body(rdata->msg_info.msg->body, body, + body_len = rdata->msg_info.msg->body->print_body(rdata->msg_info.msg->body, body, rdata->msg_info.msg->body->len + 1); + if (body_len < 0 || body_len > rdata->msg_info.msg->body->len) { + ast_debug(1, "Incoming MWI: Endpoint: '%s' Unable to print request body\n", endpoint_name); + rc = 404; + goto error; + } + body[body_len] = '\0'; + if (parse_simple_message_summary(body, &summary) != 0) { ast_debug(1, "Incoming MWI: Endpoint: '%s' There was an issue getting message info from body '%s'\n", ast_sorcery_object_get_id(endpoint), body);