==3849178==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x502000000012
WRITE of size 1 at 0x502000000012 thread T0
#0 encode_unsigned16 bacnet-stack-src/src/bacnet/bacint.c:23
#1 bvlc_encode_header bacnet-stack-src/src/bacnet/datalink/bvlc.c:42
0x502000000012 is located 0 bytes after 2-byte region [0x502000000010,0x502000000012)
uint8_t *pdu = malloc(2); // passes guard (>= 2)
bvlc_encode_header(pdu, 2, BVLC_RESULT, 10);
// ASAN: heap-buffer-overflow WRITE at pdu[2]
Description
bvlc_encode_header()inbvlc.c:36checkspdu_size >= 2but writes 4 bytes:pdu[0](type),pdu[1](function), andencode_unsigned16(&pdu[2], length)which writespdu[2]andpdu[3]. A caller passing a 2- or 3-byte buffer triggers a 1–2 byte heap overflow. Same pattern inbvlc6.c:33. Both are public API (BACNET_STACK_EXPORT).ASAN Proof
Reproduction
Fixed in PR #1467.
Credits
Kamal Sentassi (S9S Security Electronic Service)