1f6603c60Sopenharmony_ci/* 
2f6603c60Sopenharmony_ci * Copyright (c) 2023 Huawei Device Co., Ltd.
3f6603c60Sopenharmony_ci *
4f6603c60Sopenharmony_ci * Licensed under the Apache License, Version 2.0 (the "License");
5f6603c60Sopenharmony_ci * you may not use this file except in compliance with the License.
6f6603c60Sopenharmony_ci * You may obtain a copy of the License at
7f6603c60Sopenharmony_ci *
8f6603c60Sopenharmony_ci *     http://www.apache.org/licenses/LICENSE-2.0
9f6603c60Sopenharmony_ci *
10f6603c60Sopenharmony_ci * Unless required by applicable law or agreed to in writing, software
11f6603c60Sopenharmony_ci * distributed under the License is distributed on an "AS IS" BASIS,
12f6603c60Sopenharmony_ci * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13f6603c60Sopenharmony_ci * See the License for the specific language governing permissions and
14f6603c60Sopenharmony_ci * limitations under the License.
15f6603c60Sopenharmony_ci */
16f6603c60Sopenharmony_ci
17f6603c60Sopenharmony_ciimport "console"
18f6603c60Sopenharmony_ciimport "elf"
19f6603c60Sopenharmony_ci
20f6603c60Sopenharmony_ci
21f6603c60Sopenharmony_cirule OpenHarmony_SA_2023_0301
22f6603c60Sopenharmony_ci{
23f6603c60Sopenharmony_ci    meta:
24f6603c60Sopenharmony_ci    	date = "2023-03-08"
25f6603c60Sopenharmony_ci    	openharmony_sa = "OpenHarmony-SA-2023-0301"
26f6603c60Sopenharmony_ci    	cve = "CVE-2023-24465"
27f6603c60Sopenharmony_ci    	severity = "medium"
28f6603c60Sopenharmony_ci    	affacted_files = "libwifi_scan_ability.z.so"
29f6603c60Sopenharmony_ci    	affected_func = "WifiScanStub::OnScanByParams"
30f6603c60Sopenharmony_ci    	
31f6603c60Sopenharmony_ci    strings:
32f6603c60Sopenharmony_ci        $features = "run OnScanByParams code %{public}u, datasize %{public}zu" nocase wide ascii
33f6603c60Sopenharmony_ci	
34f6603c60Sopenharmony_ci	/* 3.1.4 vul code
35f6603c60Sopenharmony_ci		.text:0000B0D0 01 46                                           MOV             R1, R0
36f6603c60Sopenharmony_ci		.text:0000B0D2 20 46                                           MOV             R0, R4
37f6603c60Sopenharmony_ci	*/
38f6603c60Sopenharmony_ci		$vul = {01 46 ?? 46}
39f6603c60Sopenharmony_ci
40f6603c60Sopenharmony_ci	/* 3.1.4 with patch
41f6603c60Sopenharmony_ci		.text:0000B0DA 7D 44                                           ADD             R5, PC  ; ""
42f6603c60Sopenharmony_ci		.text:0000B0DC 08 BF                                           IT EQ
43f6603c60Sopenharmony_ci		.text:0000B0DE 29 46                                           MOVEQ           R1, R5
44f6603c60Sopenharmony_ci	*/
45f6603c60Sopenharmony_ci		$fix = {7? 44 08 BF ?? 46}
46f6603c60Sopenharmony_ci
47f6603c60Sopenharmony_ci
48f6603c60Sopenharmony_ci    condition:
49f6603c60Sopenharmony_ci        (elf.machine == elf.EM_ARM) and $features and ((not $vul) or $fix) and console.log("OpenHarmony-SA-2023-0301 testcase pass")
50f6603c60Sopenharmony_ci        
51f6603c60Sopenharmony_ci}