From ff65e4b0867bee12cdcb3a6219b976ee7ee08963 Mon Sep 17 00:00:00 2001 From: George Joseph Date: Mon, 15 Jun 2026 07:41:10 -0600 Subject: [PATCH] chan_unistim.c: Prevent overrun of phone_number field. Add a check to key_dial_page() to ensure that dialed digits won't overrun the phone_number field. Resolves: #GHSA-3g56-cgrh-95p5 --- channels/chan_unistim.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/channels/chan_unistim.c b/channels/chan_unistim.c index 08aa7bed75..ade24a597f 100644 --- a/channels/chan_unistim.c +++ b/channels/chan_unistim.c @@ -456,6 +456,8 @@ static struct unistim_device { struct unistim_device *next; } *devices = NULL; +#define MAX_PHONE_NUMBER_LENGTH (AST_MAX_EXTENSION - 1) + static struct unistimsession { ast_mutex_t lock; struct sockaddr_in sin; /*!< IP address of the phone */ @@ -3578,6 +3580,12 @@ static void key_dial_page(struct unistimsession *pte, char keycode) if ((keycode >= KEY_0) && (keycode <= KEY_SHARP)) { int i = pte->device->size_phone_number; + /* + * If the phone_number buffer is already full, bail now to prevent an overrun. + */ + if (pte->device->size_phone_number >= MAX_PHONE_NUMBER_LENGTH) { + return; + } if (pte->device->size_phone_number == 0) { send_tone(pte, 0, 0); }