1f6603c60Sopenharmony_ci/* 2f6603c60Sopenharmony_ci * Copyright (c) 2023 Huawei Device Co., Ltd. 3f6603c60Sopenharmony_ci * 4f6603c60Sopenharmony_ci * Licensed under the Apache License, Version 2.0 (the "License"); 5f6603c60Sopenharmony_ci * you may not use this file except in compliance with the License. 6f6603c60Sopenharmony_ci * You may obtain a copy of the License at 7f6603c60Sopenharmony_ci * 8f6603c60Sopenharmony_ci * http://www.apache.org/licenses/LICENSE-2.0 9f6603c60Sopenharmony_ci * 10f6603c60Sopenharmony_ci * Unless required by applicable law or agreed to in writing, software 11f6603c60Sopenharmony_ci * distributed under the License is distributed on an "AS IS" BASIS, 12f6603c60Sopenharmony_ci * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13f6603c60Sopenharmony_ci * See the License for the specific language governing permissions and 14f6603c60Sopenharmony_ci * limitations under the License. 15f6603c60Sopenharmony_ci */ 16f6603c60Sopenharmony_ci 17f6603c60Sopenharmony_ciimport "console" 18f6603c60Sopenharmony_ciimport "elf" 19f6603c60Sopenharmony_ci 20f6603c60Sopenharmony_ci 21f6603c60Sopenharmony_cirule OpenHarmony_SA_2023_0301 22f6603c60Sopenharmony_ci{ 23f6603c60Sopenharmony_ci meta: 24f6603c60Sopenharmony_ci date = "2023-03-08" 25f6603c60Sopenharmony_ci openharmony_sa = "OpenHarmony-SA-2023-0301" 26f6603c60Sopenharmony_ci cve = "CVE-2023-24465" 27f6603c60Sopenharmony_ci severity = "medium" 28f6603c60Sopenharmony_ci affacted_files = "libwifi_scan_ability.z.so" 29f6603c60Sopenharmony_ci affected_func = "WifiScanStub::OnScanByParams" 30f6603c60Sopenharmony_ci 31f6603c60Sopenharmony_ci strings: 32f6603c60Sopenharmony_ci $features = "run OnScanByParams code %{public}u, datasize %{public}zu" nocase wide ascii 33f6603c60Sopenharmony_ci 34f6603c60Sopenharmony_ci /* 3.1.4 vul code 35f6603c60Sopenharmony_ci .text:0000B0D0 01 46 MOV R1, R0 36f6603c60Sopenharmony_ci .text:0000B0D2 20 46 MOV R0, R4 37f6603c60Sopenharmony_ci */ 38f6603c60Sopenharmony_ci $vul = {01 46 ?? 46} 39f6603c60Sopenharmony_ci 40f6603c60Sopenharmony_ci /* 3.1.4 with patch 41f6603c60Sopenharmony_ci .text:0000B0DA 7D 44 ADD R5, PC ; "" 42f6603c60Sopenharmony_ci .text:0000B0DC 08 BF IT EQ 43f6603c60Sopenharmony_ci .text:0000B0DE 29 46 MOVEQ R1, R5 44f6603c60Sopenharmony_ci */ 45f6603c60Sopenharmony_ci $fix = {7? 44 08 BF ?? 46} 46f6603c60Sopenharmony_ci 47f6603c60Sopenharmony_ci 48f6603c60Sopenharmony_ci condition: 49f6603c60Sopenharmony_ci (elf.machine == elf.EM_ARM) and $features and ((not $vul) or $fix) and console.log("OpenHarmony-SA-2023-0301 testcase pass") 50f6603c60Sopenharmony_ci 51f6603c60Sopenharmony_ci}