flawopen.com/Teardowns/cve-2015-3824-android-stagefright-mediacodec-oob-write

● CVE-2015-3824 · CVSS v2 10.0 · Alta
Investigación · FlawOpen

CVE-2015-3824: Android Stagefright MediaCodec Out-of-Bounds Write Teardown

Análisis técnico del código fuente y mitigaciones de ingeniería para vulnerabilidade: How an unsigned integer wrap during H.264 NAL unit length decoding in libstagefright enabled zero-click remote code execution via video files.

💡 Explicación en Lenguaje Sencillo (ELI5)

Analogía práctica: Imagine a video projector that reads the size of each video slide from the film itself. A film has a label: 'This slide is 4 billion bytes long'. The projector calculates the size using a small pocket calculator that wraps back around to 12. It creates a tiny frame for 12 bytes, and then the film feeds 4 billion bytes into it, jamming the projector and taking over the movie theater.

Conceptos Clave y Términos

libstagefright
The Android C++ multimedia parsing engine responsible for demuxing and decoding MP4, MKV, and streaming video.
NAL Unit (Network Abstraction Layer)
The packet format used to deliver H.264/AVC and H.265/HEVC video frames.
media.codec Sandbox
The isolated Linux process where video decoding hardware acceleration runs on Android.
Zero-Click Exploit
An attack that achieves remote code execution without requiring the victim to click a link or open an application.

Análisis de Causa Raíz

La causa raíz se debe a parámetros de límite no validados en sistemas de código abierto, lo que permite la desincronización de estado y la elusión de controles de seguridad.

Flujo de Ataque Paso a Paso

Step 1

Fase de ataque: Deliver Malicious Video

Mecanismo técnico de explotación: The attacker sends a crafted MP4 video via chat or MMS.

Step 2

Fase de ataque: Background Thumbnail Parsing

Mecanismo técnico de explotación: Android's media scanner automatically demuxes the video without user interaction.

Step 3

Fase de ataque: Integer Wrap in NALU Length

Mecanismo técnico de explotación: libstagefright adds the NAL unit size to an offset, wrapping past 32 bits.

Step 4

Fase de ataque: Heap Buffer Overwrite & RCE

Mecanismo técnico de explotación: The decoder writes video data into an undersized heap buffer, achieving code execution.

Código Fuente: Vulnerable vs. Seguro

IMPLEMENTACIÓN VULNERABLE
// VULNERABLE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // ROOT CAUSE:
    // Raw unsigned 32-bit addition wraps around!
    // If chunk_size is 0xFFFFFFF0, adding header (0x20) results in 0x10 (16 bytes!)
    uint32_t alloc_size = chunk_size + sizeof(ChunkHeader);
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    // Copies full chunk_size, overflowing buffer!
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}
PARCHE SEGURO Y ROBUSTO
// SECURE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp patch
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // 1. Enforce safe integer arithmetic check using __builtin_add_overflow
    uint32_t alloc_size;
    if (__builtin_add_overflow(chunk_size, sizeof(ChunkHeader), &alloc_size)) {
        return ERROR_MALFORMED; // Abort on integer overflow
    }
    
    // 2. Impose strict maximum upper bound ceiling on media chunks
    if (alloc_size > MAX_MEDIA_CHUNK_SIZE) {
        return ERROR_MALFORMED;
    }
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}

Lista de Verificación de Seguridad para Ingeniería

Fuentes