仓库虽然注册了删除路由,但两个与本文相关的 handler 都只返回 501 Not Implemented,所以不能把它们视为已实现的上下文消费机制:
func (s *Server) HTTPDelete5gAkaAuthenticationResult(c *gin.Context) {
c.JSON(http.StatusNotImplemented, gin.H{})
}
func (s *Server) HTTPDeleteEapAuthenticationResult(c *gin.Context) {
c.JSON(http.StatusNotImplemented, gin.H{})
}
入池后字段的写入顺序(这既解释了 CodeQL 断点,也提示了潜在并发风险):
ausfUeContext := ausf_context.NewAusfUeContext(ueid)
ausfUeContext.ServingNetworkName = snName
ausfUeContext.AuthStatus = models.AusfUeAuthenticationAuthResult_ONGOING
ausfUeContext.UdmUeauUrl = udmUrl
ausf_context.AddAusfUeContextToPool(ausfUeContext)
logger.UeAuthLog.Infof("Add SuciSupiPair (%s, %s) to map.\n", supiOrSuci, ueid)
ausf_context.AddSuciSupiPairToMap(supiOrSuci, ueid)
locationURI := self.Url + factory.AusfAuthResUriPrefix + "/ue-authentications/" + supiOrSuci
putLink := locationURI
switch authInfoResult.AuthType {
case models.UdmUeauAuthType__5_G_AKA:
ausfUeContext.XresStar = authInfoResult.AuthenticationVector.XresStar
ausfUeContext.Kausf = Kausf
ausfUeContext.Kseaf = hex.EncodeToString(Kseaf)
ausfUeContext.Rand = authInfoResult.AuthenticationVector.Rand
}
sync.Map 的 Store/Load 只保证映射操作本身的并发安全,不会同步存入指针所指字段的后续写入。若确认请求恰好在 internal/sbi/processor/ue_authentication.go:363–427 的窗口中取回对象,可能读到零值,亦可能形成数据竞争。本文未通过 -race 或并发实验将其确认为独立漏洞,因此仅将其列为需要单独验证的并发风险。
专业黑客业务:渗透网站/网址 棋牌入侵破解 脚本搭建 ddos攻击/cc攻击 舆论删除/负面删除 BC博彩/投顾/股票/电子签/贷款/各类资料 学信网录入/改分/改档案 盘口改单/不中改中 域名劫持/Dns劫持 Pg赔率/爆率 Gov站点业务
技术小黄鸭🟡:@Xiaohyaa