jerpelea opened a new pull request, #20358:
URL: https://github.com/apache/nuttx/pull/20358

   ## Summary
   
   Two problems in hci_num_completed_packets().
   
   Number_of_Handles is a single octet, but it was read with BT_LE162HOST(), 
which takes the first octet of the handle that follows it as the high byte.  A 
one-octet field could therefore produce a loop count of up to 65535.
   
   The loop was then bounded only by that count and not by the data that was 
actually received, so it walked past the end of the event, reading handle and 
count pairs out of whatever followed it.
   
   Read the field at its declared width, and require the pairs the event claims 
to have been received before reading them.
   
   Per-connection credit accounting, which this handler still does not do, is a 
separate change.
   
   Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event) 
Testing: builds for sim:bluetooth with Make; every commit in this series 
verified to build individually.
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to