Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The case is, in uxhostclasspima_read, there is data length from device response, returned in the very first packet, and read by L165 code, as headerlength. Then in L178 code, there is a “if” branch, which check the expression of “(headerlength - UXHOSTCLASSPIMADATAHEADERSIZE) > datalength” where if headerlength is smaller than UXHOSTCLASSPIMADATAHEADERSIZE, calculation could overflow and then L182 code the calculation of datalength is also overflow, this way the later while loop start from L192 can move datapointer to unexpected address and cause write buffer overflow. The fix has been included in USBX release 6.1.12. The following can be used as a workaround: Add check of header_length: 1. It must be greater than UX_HOST_CLASS_PIMA_DATA_HEADER_SIZE. 1. It should be greater or equal to the current returned data length (transfer_request -> ux_transfer_request_actual_length).
{
"cwe_ids": [
"CWE-191"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39293.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:eclipse:threadx_usbx:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.1.12"
}
],
"source": [
"AFFECTED_FIELD",
"CPE_RANGE",
"REFERENCES"
]
}