mirror of
https://github.com/open5gs/open5gs.git
synced 2026-07-31 10:44:11 +00:00
|
Some checks failed
Meson Continuous Integration / Build and Test on Ubuntu Latest (push) Has been cancelled
TS 23.003 limits an IMSI to 15 decimal digits, but several identity conversion paths accepted overlong or non-decimal values. Validate null-scheme SUCI MSINs before constructing SUCI and SUPI strings. Centralize SUCI validation in the NAS conversion helper and propagate failures through AMF Registration Request and Identity Response handling with 5GMM cause 95. Keep detailed error logging at each failure stage. Validate MCC, MNC and MSIN components when reconstructing an IMSI SUPI in the SBI layer, and improve UDM logging when SUCI conversion fails. Validate EPS IMSIs before modifying MME context or hash state. Reject non-decimal BCD values and invalid IMSI lengths in Attach Request and Identity Response handling. Also validate the peer-controlled IMSI IE in Gn SGSN Context Request and Response messages. An 8-octet TBCD value without a filler nibble decodes to 16 digits plus a trailing NUL, which overflowed the previous 16-byte stack buffer before validation. Use a 17-byte temporary decode buffer, reject IMSI IEs longer than 8 octets, and continue enforcing the 15-digit IMSI limit after conversion. Update registration tests to normalize MSIN padding only for null-scheme SUCIs, preserve protected scheme output, assert successful test SUCI conversion, record returned GMM causes, and verify rejection of an overlong SUCI. |
||
|---|---|---|
| .. | ||
| 310014 | ||
| af | ||
| app | ||
| attach | ||
| common | ||
| core | ||
| crypt | ||
| csfb | ||
| fuzzing | ||
| handover | ||
| non3gpp | ||
| registration | ||
| sctp | ||
| slice | ||
| transfer | ||
| unit | ||
| volte | ||
| vonr | ||
| meson.build | ||