nuttx/wireless
Alan Carvalho de Assis 843cf6d581 wireless/bluetooth: Validate Number Of Completed Packets event.
Two problems in hci_num_completed_packets().

Number_of_Handles is a single octet, but it was read with BT_LE162HOST(),
which takes the first octet of the handle that follows it as the high
byte.  A one-octet field could therefore produce a loop count of up to
65535.

The loop was then bounded only by that count and not by the data that was
actually received, so it walked past the end of the event, reading handle
and count pairs out of whatever followed it.

Read the field at its declared width, and require the pairs the event
claims to have been received before reading them.

Per-connection credit accounting, which this handler still does not do,
is a separate change.

Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-25 10:35:51 +02:00
..
bluetooth wireless/bluetooth: Validate Number Of Completed Packets event. 2026-09-25 10:35:51 +02:00
ieee802154 drivers/: Multiple Drivers Are Registered With World Writable - Part 2 2026-07-15 15:27:28 +08:00
pktradio include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig Kconfig: add quotes in source to clean warnings from setconfig 2021-07-23 02:32:19 -07:00
Makefile tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00