mirror of
https://github.com/apache/nuttx.git
synced 2026-09-29 10:34:23 +00:00
hci_event() consumed the event header and dispatched on the event code without checking that a header had been received, and hci_le_meta_event() did the same for the subevent code. Each handler then cast the remaining buffer to its event structure and read fields out of it, so a short event was parsed from whatever followed it in memory - including the fields that identify a connection and carry its encryption state. Check that the header is present before reading it, that the parameters the event declares were actually received, and that enough parameters remain for the structure the selected handler casts to. Events failing a check are dropped with a diagnostic rather than parsed. le_adv_report() continues to do its own checking, because the report count and the per-report lengths vary within that event. Ref: Core v6.0, Vol 4, Part E, 5.4.4 (HCI Event packets) Ref: Core v6.0, Vol 4, Part E, 7.7 (Events) Testing: builds for sim:bluetooth with Make; every commit in this series verified to build individually. Not yet exercised at runtime - the scriptable controller injects truncated events separately. Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5 |
||
|---|---|---|
| .. | ||
| bluetooth | ||
| ieee802154 | ||
| pktradio | ||
| CMakeLists.txt | ||
| Kconfig | ||
| Makefile | ||