Skip to content

BVLC Header Encoder Out-of-Bounds Write (BN-06)

High
skarg published GHSA-3q5x-2r73-c55v Oct 4, 2026

Software

bacnet-stack

Affected versions

<= 1.6.0

Patched versions

1.4.6,1.5.2,1.6.1

Description

Description

bvlc_encode_header() in bvlc.c:36 checks pdu_size >= 2 but writes 4 bytes: pdu[0] (type), pdu[1] (function), and encode_unsigned16(&pdu[2], length) which writes pdu[2] and pdu[3]. A caller passing a 2- or 3-byte buffer triggers a 1–2 byte heap overflow. Same pattern in bvlc6.c:33. Both are public API (BACNET_STACK_EXPORT).

ASAN Proof

==3849178==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x502000000012
WRITE of size 1 at 0x502000000012 thread T0
    #0 encode_unsigned16 bacnet-stack-src/src/bacnet/bacint.c:23
    #1 bvlc_encode_header bacnet-stack-src/src/bacnet/datalink/bvlc.c:42
0x502000000012 is located 0 bytes after 2-byte region [0x502000000010,0x502000000012)

Reproduction

uint8_t *pdu = malloc(2);  // passes guard (>= 2)
bvlc_encode_header(pdu, 2, BVLC_RESULT, 10);
// ASAN: heap-buffer-overflow WRITE at pdu[2]

Fixed in PR #1467.

Credits

Kamal Sentassi (S9S Security Electronic Service)

Severity

High

CVE ID

No known CVE

Weaknesses

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer. Learn more on MITRE.

Credits