This is an automated email from the ASF dual-hosted git repository.

acassis pushed a commit to branch releases/13.1
in repository https://gitbox.apache.org/repos/asf/nuttx.git


The following commit(s) were added to refs/heads/releases/13.1 by this push:
     new e406ecd0a0e wireless/bluetooth: Validate Number Of Completed Packets 
event.
e406ecd0a0e is described below

commit e406ecd0a0e4ed0593c2954275c886de29e6cfe5
Author: Alan Carvalho de Assis <[email protected]>
AuthorDate: Thu Sep 17 10:20:37 2026 -0300

    wireless/bluetooth: Validate Number Of Completed Packets event.
    
    Two problems in hci_num_completed_packets().
    
    Number_of_Handles is a single octet, but it was read with BT_LE162HOST(),
    which takes the first octet of the handle that follows it as the high
    byte.  A one-octet field could therefore produce a loop count of up to
    65535.
    
    The loop was then bounded only by that count and not by the data that was
    actually received, so it walked past the end of the event, reading handle
    and count pairs out of whatever followed it.
    
    Read the field at its declared width, and require the pairs the event
    claims to have been received before reading them.
    
    Per-connection credit accounting, which this handler still does not do,
    is a separate change.
    
    Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event)
    Testing: builds for sim:bluetooth with Make; every commit in this series
    verified to build individually.
    
    Signed-off-by: Alan C. Assis <[email protected]>
    Assisted-by: Claude Code Opus 5
---
 wireless/bluetooth/bt_hcicore.c | 28 ++++++++++++++++++++++++++--
 1 file changed, 26 insertions(+), 2 deletions(-)

diff --git a/wireless/bluetooth/bt_hcicore.c b/wireless/bluetooth/bt_hcicore.c
index 8705a08fae6..cf8625d80e3 100644
--- a/wireless/bluetooth/bt_hcicore.c
+++ b/wireless/bluetooth/bt_hcicore.c
@@ -432,8 +432,32 @@ static void hci_cmd_status(FAR struct bt_buf_s *buf)
 static void hci_num_completed_packets(FAR struct bt_buf_s *buf)
 {
   FAR struct bt_hci_evt_num_completed_packets_s *evt = (FAR void *)buf->data;
-  uint16_t num_handles = BT_LE162HOST(evt->num_handles);
-  uint16_t i;
+  uint8_t num_handles;
+  uint8_t i;
+
+  if (buf->len < sizeof(*evt))
+    {
+      wlerr("ERROR: Truncated Number Of Completed Packets event\n");
+      return;
+    }
+
+  /* Number_of_Handles is one octet.  Reading it with BT_LE162HOST() took
+   * the first octet of the following handle as its high byte, so a count
+   * of up to 65535 could be produced from a one-octet field.
+   */
+
+  num_handles = evt->num_handles;
+
+  /* The handle and count pairs the event declares have to have been
+   * received before they can be read.
+   */
+
+  if (buf->len < sizeof(*evt) + num_handles * sizeof(evt->h[0]))
+    {
+      wlerr("ERROR: Event declares %u handles but carries %u octets\n",
+            num_handles, buf->len);
+      return;
+    }
 
   wlinfo("num_handles %u\n", num_handles);
 

Reply via email to