Skip to content

fix(p2p): bound sscanf field widths in tuya_sdp.c to prevent stack overflow - #726

Merged
shiliu-yang merged 1 commit into
tuya:masterfrom
maidang-xing:fix/p2p-sdp-sscanf-stack-overflow
Sep 30, 2026
Merged

shiliu-yang merged 1 commit into
tuya:masterfrom
maidang-xing:fix/p2p-sdp-sscanf-stack-overflow

Conversation

@maidang-xing

Copy link
Copy Markdown
Contributor

Problem

tuya_p2p_rtc_sdp_decode() in src/tuya_p2p/base_ice/src/tuya_sdp.c parses SDP lines received from the remote P2P peer using sscanf() with unbounded %s conversions into fixed-size stack buffers:

Line SDP line Buffers
L948 a=msid-semantic: wms_name[65], wms_id[65]
L959 a=msid: msid[65], track_id[65]
L975 a=group:BUNDLE m1[65], m2[65], m3[65]
L1070 a=fmtp: str_pt[32], str_attr[256]
L1084 a=ssrc-group:FID ssrc[65], ssrc_rtx[65]

An attacker on the peer side controls the SDP answer and can send an arbitrarily long token in any of these lines, overflowing the stack buffers and potentially achieving remote code execution.

Fix

Add maximum field widths (size - 1) to every %s conversion so each token is safely truncated to the destination buffer size:

-    int cnt = sscanf(p, "%s %s", wms_name, wms_id);
+    int cnt = sscanf(p, "%64s %64s", wms_name, wms_id);

No parsing behavior changes for well-formed SDP (real tokens are far shorter than the limits).

Verification

Compiled tuya_sdp.c standalone with stubs and exercised tuya_p2p_rtc_sdp_decode() under AddressSanitizer with a malicious SDP containing 200-byte/300-byte tokens in all five affected lines:

  • Before fix: AddressSanitizer: stack-buffer-overflow, WRITE of 201 bytes into wms_id (char[65]) at tuya_sdp.c:948 — crashes exactly at the reported location
  • After fix: decode completes cleanly, tokens truncated to buffer size, no sanitizer reports
==ERROR: AddressSanitizer: stack-buffer-overflow
WRITE of size 201
    #3 tuya_p2p_rtc_sdp_decode tuya_sdp.c:948

Also confirmed the remaining sscanf calls in src/tuya_p2p/ are either numeric-only or already width-limited (%63s in local_store.c).

…erflow

tuya_p2p_rtc_sdp_decode() parsed attacker-controlled SDP attributes with
unbounded "%s" conversions into fixed-size stack buffers (wms_name, wms_id,
msid, track_id, m1-m3, str_pt, str_attr, ssrc, ssrc_rtx). A malicious P2P
peer could send overlong tokens in SDP lines such as "a=msid-semantic:" and
overflow these buffers, corrupting the stack and potentially achieving
remote code execution.

Add maximum field widths (size - 1) to every %s conversion so input is
safely truncated to the destination buffer size. Verified with an
AddressSanitizer PoC that the original code crashes with a
stack-buffer-overflow (WRITE of 201 bytes into char[65]) while the patched
code parses the same malicious SDP cleanly.
@maidang-xing
maidang-xing force-pushed the fix/p2p-sdp-sscanf-stack-overflow branch from 0df6b8a to a0789b2 Compare September 30, 2026 06:00
@shiliu-yang
shiliu-yang merged commit b1d3aec into tuya:master Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants