Skip to content

Eclipse ThreadX USBX v6.5.2.202603

Latest

Choose a tag to compare

@fdesbiens fdesbiens released this 02 Oct 19:06
d947676

This release fixes three out-of-bounds reads in the host classes, each of them reached by a device reporting a length larger than the buffer the host sized for it. Four APIs are flagged as deprecated.

We thank contributors from Causal Security and STMicroelectronics, along with the independent contributors @acorn421, @adawn0106 and @Microsvuln, for their valuable contributions to this release.

The USBX user guide is attached to this release as a PDF, in A4 and US Letter.

Vulnerabilities addressed

Three vulnerabilities are fixed in 6.5.2.202603. All three share a shape: a value taken from the device is used as a bound without being checked against the buffer that actually holds the data, so a malicious or malfunctioning peripheral reads host memory past the end of a descriptor or response. Attaching the device is the whole of the attack.

All three affect every release up to and including 6.5.1.202602, and all are fixed in 6.5.2.202603.

The PIMA defect was reported by @Microsvuln, the VIDEO one by @cipher-creator of Causal Security, and the HID one by @cipher-creator, @acorn421, @adawn0106 and @rahmanih.

Each advisory ships regression tests that fail when its fix is reverted. One exception is recorded in the source: the bound in _ux_host_class_video_activate is the same condition as the one covered in _ux_host_class_video_input_format_get, and the status it propagates comes from _ux_host_class_video_entities_parse, which is also covered; the call site composing the two is not separately tested, because reaching it needs a simulated host and device stack.

You can access advisories for previously addressed vulnerabilities here.

Highlights

The host classes no longer trust a device's own lengths

The three defects are the same mistake in three places. A PIMA device reports how many object handles follow; the host sized a buffer for a maximum and then read the reported count out of it. A VIDEO device reports wTotalLength for its format block; the host walked that far regardless of how much configuration descriptor remained. A HID device declares the size of each report item's data; the parser advanced first and checked afterwards.

In each case the fix is the same: bound the walk by the buffer the host allocated rather than by the number the device supplied, and refuse the descriptor when the two disagree. The VIDEO fix also stops a corrupted-descriptor result from being reported to the caller as a successful parse.

Deprecations

Four USBX APIs are flagged as deprecated. (#269, @fdesbiens)

Other Changes

  • Removed a stray byte order mark that broke the regression build (#274, @fdesbiens)
  • Updated the security policy (#270, @fdesbiens)
  • Stopped the release script adding a Co-authored-by trailer, which asserts an authorship an AI cannot hold (#282, @fdesbiens)

Full Changelog: v6.5.1.202602_rel...v6.5.2.202603_rel