jerpelea opened a new pull request, #20317:
URL: https://github.com/apache/nuttx/pull/20317

   ## Summary
   
   bt_conn_receive() read the 4-octet L2CAP header out of the first fragment of 
a PDU without checking that 4 octets had been received, and then computed the 
outstanding length by subtracting the fragment length from the declared PDU 
length.
   
   Two problems follow. A fragment shorter than the header was parsed from 
whatever happened to follow it in the buffer. And a fragment carrying more data 
than the PDU it declares made the subtraction wrap, because conn->rx_len is 16 
bits: the connection was then left expecting up to 65535 further octets, 
holding the partial PDU and accumulating later fragments against an expectation 
that could never be satisfied.
   
   Check that the fragment is long enough to hold a header before reading it, 
and that it does not exceed the PDU it declares before computing what remains. 
Drop the fragment and reset the reassembly state otherwise.
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to