Skip to content

Integer Overflow in Tag Counter leads to Heap Buffer Overflow (BN-01)

Critical
skarg published GHSA-g2r7-4c8g-qx5p Aug 13, 2026

Software

bacnet-stack

Affected versions

<= 1.6.0

Patched versions

1.4.6,1.5.2,1.6.1

Description

Description

bacnet_enclosed_data_length() in bacdcode.c:827 uses a uint8_t counter for nested opening tags. 256 nested tags of the same tag number wrap the counter from 255 to 0, causing the loop to exit early. The function returns 254 instead of the actual length (~612). Callers that allocate based on this value create an undersized buffer; the subsequent memcpy writes 612 bytes into a 254-byte allocation.

ASAN Proof

==3849388==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51100000013e
WRITE of size 612 at 0x51100000013e thread T0
    #0 memcpy
    #1 test_bn01 poc-bacnet-asan-v2.c:123
0x51100000013e is located 0 bytes after 254-byte region [0x511000000040,0x51100000013e)

Reproduction

// 256 opening tags + payload + 256 closing tags = 612 bytes
int reported = bacnet_enclosed_data_length(apdu, 612);
// reported = 254 (WRONG — counter wrapped)
uint8_t *buf = malloc(reported);  // 254 bytes
memcpy(buf, apdu, 612);           // ASAN: heap-buffer-overflow WRITE

Fixed in PR #1466.

Credits

Kamal Sentassi (S9S Security Electronic Service)

Severity

Critical

CVE ID

No known CVE

Weaknesses

Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number. Learn more on MITRE.

Credits