==3849388==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x51100000013e
WRITE of size 612 at 0x51100000013e thread T0
#0 memcpy
#1 test_bn01 poc-bacnet-asan-v2.c:123
0x51100000013e is located 0 bytes after 254-byte region [0x511000000040,0x51100000013e)
// 256 opening tags + payload + 256 closing tags = 612 bytes
int reported = bacnet_enclosed_data_length(apdu, 612);
// reported = 254 (WRONG — counter wrapped)
uint8_t *buf = malloc(reported); // 254 bytes
memcpy(buf, apdu, 612); // ASAN: heap-buffer-overflow WRITE
Description
bacnet_enclosed_data_length()inbacdcode.c:827uses auint8_tcounter for nested opening tags. 256 nested tags of the same tag number wrap the counter from 255 to 0, causing the loop to exit early. The function returns 254 instead of the actual length (~612). Callers that allocate based on this value create an undersized buffer; the subsequent memcpy writes 612 bytes into a 254-byte allocation.ASAN Proof
Reproduction
Fixed in PR #1466.
Credits
Kamal Sentassi (S9S Security Electronic Service)