flawopen.com/Teardowns/cve-2015-3824-android-stagefright-mediacodec-oob-write

● CVE-2015-3824 · CVSS v2 10.0 · उच्च
सुरक्षा अनुसंधान · FlawOpen

तकनीकी विश्लेषण: CVE-2015-3824: Android Stagefright MediaCodec Out-of-Bounds Write Teardown

vulnerabilidade का गहन तकनीकी स्रोत कोड विश्लेषण और सुरक्षा सुदृढ़ीकरण गाइड: भेद्यता के मूल कारण और सुरक्षित पैच की समीक्षा।

💡 आसान भाषा में (ELI5)

सरल भौतिक उपमा द्वारा समझें: Imagine a video projector that reads the size of each video slide from the film itself. A film has a label: 'This slide is 4 billion bytes long'. The projector calculates the size using a small pocket calculator that wraps back around to 12. It creates a tiny frame for 12 bytes, and then the film feeds 4 billion bytes into it, jamming the projector and taking over the movie theater.

इस पेज के मुख्य शब्द

libstagefright
The Android C++ multimedia parsing engine responsible for demuxing and decoding MP4, MKV, and streaming video.
NAL Unit (Network Abstraction Layer)
The packet format used to deliver H.264/AVC and H.265/HEVC video frames.
media.codec Sandbox
The isolated Linux process where video decoding hardware acceleration runs on Android.
Zero-Click Exploit
An attack that achieves remote code execution without requiring the victim to click a link or open an application.

मूल कारण विश्लेषण (Root Cause)

मूल कारण ओपन सोर्स सिस्टम में अनसत्यापित सीमा पैरामीटर हैं, जिससे स्थिति का असंतुलन और सुरक्षा नियंत्रणों को बायपास किया जा सकता है।

हमले का चरण-दर-चरण प्रवाह

Step 1

हमला चरण: Deliver Malicious Video

तकनीकी शोषण तंत्र और निष्पादन विवरण: The attacker sends a crafted MP4 video via chat or MMS.

Step 2

हमला चरण: Background Thumbnail Parsing

तकनीकी शोषण तंत्र और निष्पादन विवरण: Android's media scanner automatically demuxes the video without user interaction.

Step 3

हमला चरण: Integer Wrap in NALU Length

तकनीकी शोषण तंत्र और निष्पादन विवरण: libstagefright adds the NAL unit size to an offset, wrapping past 32 bits.

Step 4

हमला चरण: Heap Buffer Overwrite & RCE

तकनीकी शोषण तंत्र और निष्पादन विवरण: The decoder writes video data into an undersized heap buffer, achieving code execution.

सोर्स कोड: कमज़ोर बनाम सुरक्षित कार्यान्वयन

कमज़ोर कार्यान्वयन
// VULNERABLE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // ROOT CAUSE:
    // Raw unsigned 32-bit addition wraps around!
    // If chunk_size is 0xFFFFFFF0, adding header (0x20) results in 0x10 (16 bytes!)
    uint32_t alloc_size = chunk_size + sizeof(ChunkHeader);
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    // Copies full chunk_size, overflowing buffer!
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}
सुरक्षित और सुदृढ़ फ़िक्स
// SECURE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp patch
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // 1. Enforce safe integer arithmetic check using __builtin_add_overflow
    uint32_t alloc_size;
    if (__builtin_add_overflow(chunk_size, sizeof(ChunkHeader), &alloc_size)) {
        return ERROR_MALFORMED; // Abort on integer overflow
    }
    
    // 2. Impose strict maximum upper bound ceiling on media chunks
    if (alloc_size > MAX_MEDIA_CHUNK_SIZE) {
        return ERROR_MALFORMED;
    }
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}

इंजीनियरिंग और सिस्टम सुरक्षा चेकलिस्ट

स्रोत