jerpelea opened a new pull request, #20338:
URL: https://github.com/apache/nuttx/pull/20338

   ## Summary
   
   hci_event() consumed the event header and dispatched on the event code 
without checking that a header had been received, and hci_le_meta_event() did 
the same for the subevent code.  Each handler then cast the remaining buffer to 
its event structure and read fields out of it, so a short event was parsed from 
whatever followed it in memory - including the fields that identify a 
connection and carry its encryption state.
   
   Check that the header is present before reading it, that the parameters the 
event declares were actually received, and that enough parameters remain for 
the structure the selected handler casts to.  Events failing a check are 
dropped with a diagnostic rather than parsed.
   
   le_adv_report() continues to do its own checking, because the report count 
and the per-report lengths vary within that event.
   
   Ref: Core v6.0, Vol 4, Part E, 5.4.4 (HCI Event packets) Ref: Core v6.0, Vol 
4, Part E, 7.7 (Events)
   Testing: builds for sim:bluetooth with Make; every commit in this series 
verified to build individually.  Not yet exercised at runtime - the scriptable 
controller injects truncated events separately.
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to