flawopen.com/Teardowns/cve-2015-3824-android-stagefright-mediacodec-oob-write

● CVE-2015-3824 · CVSS v2 10.0 · Tinggi
Riset Keamanan · FlawOpen

CVE-2015-3824: Android Stagefright MediaCodec Out-of-Bounds Write Teardown

Analisis teknis mendalam dan mitigasi rekayasa sistem untuk vulnerabilidade: How an unsigned integer wrap during H.264 NAL unit length decoding in libstagefright enabled zero-click remote code execution via video files.

💡 Penjelasan Sederhana (ELI5)

Analogi dunia nyata: Imagine a video projector that reads the size of each video slide from the film itself. A film has a label: 'This slide is 4 billion bytes long'. The projector calculates the size using a small pocket calculator that wraps back around to 12. It creates a tiny frame for 12 bytes, and then the film feeds 4 billion bytes into it, jamming the projector and taking over the movie theater.

Konsep Kunci & Istilah

libstagefright
The Android C++ multimedia parsing engine responsible for demuxing and decoding MP4, MKV, and streaming video.
NAL Unit (Network Abstraction Layer)
The packet format used to deliver H.264/AVC and H.265/HEVC video frames.
media.codec Sandbox
The isolated Linux process where video decoding hardware acceleration runs on Android.
Zero-Click Exploit
An attack that achieves remote code execution without requiring the victim to click a link or open an application.

Analisis Akar Masalah (Root Cause)

Akar masalah bermula dari parameter batas yang tidak divalidasi pada sistem open source, yang memungkinkan desinkronisasi status dan bypass kontrol keamanan.

Alur Serangan Langkah demi Langkah

Step 1

Tahap serangan: Deliver Malicious Video

Mekanisme eksploitasi teknis dan detail eksekusi: The attacker sends a crafted MP4 video via chat or MMS.

Step 2

Tahap serangan: Background Thumbnail Parsing

Mekanisme eksploitasi teknis dan detail eksekusi: Android's media scanner automatically demuxes the video without user interaction.

Step 3

Tahap serangan: Integer Wrap in NALU Length

Mekanisme eksploitasi teknis dan detail eksekusi: libstagefright adds the NAL unit size to an offset, wrapping past 32 bits.

Step 4

Tahap serangan: Heap Buffer Overwrite & RCE

Mekanisme eksploitasi teknis dan detail eksekusi: The decoder writes video data into an undersized heap buffer, achieving code execution.

Kode Sumber: Rentan vs Aman

IMPLEMENTASI RENTAN
// VULNERABLE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // ROOT CAUSE:
    // Raw unsigned 32-bit addition wraps around!
    // If chunk_size is 0xFFFFFFF0, adding header (0x20) results in 0x10 (16 bytes!)
    uint32_t alloc_size = chunk_size + sizeof(ChunkHeader);
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    // Copies full chunk_size, overflowing buffer!
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}
PERBAIKAN AMAN & KUAT
// SECURE: frameworks/av/media/libstagefright/MPEG4Extractor.cpp patch
status_t MPEG4Extractor::parseChunk(off64_t *offset) {
    uint32_t chunk_size = readU32();
    
    // 1. Enforce safe integer arithmetic check using __builtin_add_overflow
    uint32_t alloc_size;
    if (__builtin_add_overflow(chunk_size, sizeof(ChunkHeader), &alloc_size)) {
        return ERROR_MALFORMED; // Abort on integer overflow
    }
    
    // 2. Impose strict maximum upper bound ceiling on media chunks
    if (alloc_size > MAX_MEDIA_CHUNK_SIZE) {
        return ERROR_MALFORMED;
    }
    
    uint8_t *buffer = (uint8_t *)malloc(alloc_size);
    mDataSource->readAt(*offset, buffer, chunk_size);
    return OK;
}

Daftar Periksa Penguatan Sistem Rekayasa

Sumber