flawopen.com/Teardowns/cve-2015-3824-android-stagefright-mediacodec-oob-write

● CVE-2015-3824 · CVSS v2 10.0 · Haute
Recherche · FlawOpen

CVE-2015-3824: Android Stagefright MediaCodec Out-of-Bounds Write Teardown

Analyse technique détaillée du code source et mesures de durcissement pour vulnerabilidade : How an unsigned integer wrap during H.264 NAL unit length decoding in libstagefright enabled zero-click remote code execution via video files.

💡 Explication en Langage Simple (ELI5)

Analogie concrète : Imagine a video projector that reads the size of each video slide from the film itself. A film has a label: 'This slide is 4 billion bytes long'. The projector calculates the size using a small pocket calculator that wraps back around to 12. It creates a tiny frame for 12 bytes, and then the film feeds 4 billion bytes into it, jamming the projector and taking over the movie theater.

Concepts Clés et Termes

libstagefright
The Android C++ multimedia parsing engine responsible for demuxing and decoding MP4, MKV, and streaming video.
NAL Unit (Network Abstraction Layer)
The packet format used to deliver H.264/AVC and H.265/HEVC video frames.
media.codec Sandbox
The isolated Linux process where video decoding hardware acceleration runs on Android.
Zero-Click Exploit
An attack that achieves remote code execution without requiring the victim to click a link or open an application.

Analyse de Cause Racine

La cause fondamentale provient de paramètres de limites non validés dans les systèmes open source, permettant une désynchronisation d'état et le contournement des contrôles de sécurité.

Déroulement de l'Attaque Étape par Étape

Step 1

Étape d'attaque : Deliver Malicious Video

Mécanisme technique d'exploitation : The attacker sends a crafted MP4 video via chat or MMS.

Step 2

Étape d'attaque : Background Thumbnail Parsing

Mécanisme technique d'exploitation : Android's media scanner automatically demuxes the video without user interaction.

Step 3

Étape d'attaque : Integer Wrap in NALU Length

Mécanisme technique d'exploitation : libstagefright adds the NAL unit size to an offset, wrapping past 32 bits.

Step 4

Étape d'attaque : Heap Buffer Overwrite & RCE

Mécanisme technique d'exploitation : The decoder writes video data into an undersized heap buffer, achieving code execution.

Code Source : Vulnérable vs Sécurisé

IMPLÉMENTATION VULNÉRABLE
// VULNERABLE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // ROOT CAUSE:
    // Raw unsigned 32-bit addition wraps around!
    // If chunk_size is 0xFFFFFFF0, adding header (0x20) results in 0x10 (16 bytes!)
    uint32_t alloc_size = chunk_size + sizeof(ChunkHeader);
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    // Copies full chunk_size, overflowing buffer!
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}
PATCH SÉCURISÉ ET ROBUSTE
// SECURE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp patch
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // 1. Enforce safe integer arithmetic check using __builtin_add_overflow
    uint32_t alloc_size;
    if (__builtin_add_overflow(chunk_size, sizeof(ChunkHeader), &alloc_size)) {
        return ERROR_MALFORMED; // Abort on integer overflow
    }
    
    // 2. Impose strict maximum upper bound ceiling on media chunks
    if (alloc_size > MAX_MEDIA_CHUNK_SIZE) {
        return ERROR_MALFORMED;
    }
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}

Liste de Contrôle de Sécurité pour l'Ingénierie

Sources