nuttx/wireless
Alan Carvalho de Assis c728586a48 wireless/bluetooth: Validate event length before parsing HCI events.
hci_event() consumed the event header and dispatched on the event code
without checking that a header had been received, and hci_le_meta_event()
did the same for the subevent code.  Each handler then cast the remaining
buffer to its event structure and read fields out of it, so a short event
was parsed from whatever followed it in memory - including the fields
that identify a connection and carry its encryption state.

Check that the header is present before reading it, that the parameters
the event declares were actually received, and that enough parameters
remain for the structure the selected handler casts to.  Events failing a
check are dropped with a diagnostic rather than parsed.

le_adv_report() continues to do its own checking, because the report
count and the per-report lengths vary within that event.

Ref: Core v6.0, Vol 4, Part E, 5.4.4 (HCI Event packets)
Ref: Core v6.0, Vol 4, Part E, 7.7 (Events)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller injects truncated events separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-23 08:58:44 -03:00
..
bluetooth wireless/bluetooth: Validate event length before parsing HCI events. 2026-09-23 08:58:44 -03:00
ieee802154 drivers/: Multiple Drivers Are Registered With World Writable - Part 2 2026-07-15 15:27:28 +08:00
pktradio include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig Kconfig: add quotes in source to clean warnings from setconfig 2021-07-23 02:32:19 -07:00
Makefile tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00