jerpelea opened a new pull request, #20317: URL: https://github.com/apache/nuttx/pull/20317
## Summary bt_conn_receive() read the 4-octet L2CAP header out of the first fragment of a PDU without checking that 4 octets had been received, and then computed the outstanding length by subtracting the fragment length from the declared PDU length. Two problems follow. A fragment shorter than the header was parsed from whatever happened to follow it in the buffer. And a fragment carrying more data than the PDU it declares made the subtraction wrap, because conn->rx_len is 16 bits: the connection was then left expecting up to 65535 further octets, holding the partial PDU and accumulating later fragments against an expectation that could never be satisfied. Check that the fragment is long enough to hold a header before reading it, and that it does not exceed the PDU it declares before computing what remains. Drop the fragment and reset the reassembly state otherwise. ## Impact RELEASE ## Testing CI -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
