Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Alan Carvalho de Assis 9d12f6ccc6 wireless/bluetooth: Validate the L2CAP header on the first ACL fragment.
bt_conn_receive() read the 4-octet L2CAP header out of the first fragment
of a PDU without checking that 4 octets had been received, and then
computed the outstanding length by subtracting the fragment length from
the declared PDU length.

Two problems follow.  A fragment shorter than the header was parsed from
whatever happened to follow it in the buffer.  And a fragment carrying
more data than the PDU it declares made the subtraction wrap, because
conn->rx_len is 16 bits: the connection was then left expecting up to
65535 further octets, holding the partial PDU and accumulating later
fragments against an expectation that could never be satisfied.

Check that the fragment is long enough to hold a header before reading
it, and that it does not exceed the PDU it declares before computing what
remains.  Drop the fragment and reset the reassembly state otherwise.

Ref: Core v6.0, Vol 3, Part A, 3.1 (B-frame format)
Ref: Core v6.0, Vol 4, Part E, 5.4.2 (HCI ACL Data packets)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller adds the truncated and oversized fragment cases
separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-22 10:07:09 -03:00
.github build(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 2026-09-21 16:28:50 +08:00
arch arch/arm/imxrt: add a CAAM-backed /dev/random driver 2026-09-22 09:37:17 -03:00
audio audio: limit the buffer count guard to shared ring requests 2026-08-05 07:58:53 +02:00
binfmt libs/libc/elf, binfmt: Describe the GOT by base and size, not by index. 2026-09-08 16:31:16 -03:00
boards stm32l5: Fix nxstyle errors in drivers and board LEDs 2026-09-22 09:21:35 -03:00
cmake cmake: fix undefined function name in parse args error messages 2026-09-11 21:15:22 +08:00
crypto crypto: fix chacha constants under GCC 15. 2026-09-20 08:22:11 -03:00
Documentation Documentation/platforms/arm/rtl8730e: update board doc and add gpio config 2026-09-22 09:18:16 -03:00
drivers sensors/lsm6ds3trc: recover from a failed FIFO drain instead of wedging 2026-09-22 13:50:01 +08:00
dummy build: add initial cmake build system 2023-07-08 13:50:48 +08:00
fs docs: document chroot jail root 2026-09-20 22:27:38 +08:00
graphics graphics/nxterm: consume SGR escape sequences 2026-08-23 10:46:02 +08:00
include drivers/vhost: Add vhost-net, a device-role virtio network driver. 2026-09-21 10:40:13 -03:00
libs libc/elf: Always free the module symbol table on removal. 2026-09-22 13:29:57 +08:00
mm mm/iob: fix CONFIG_NET_TIMESTAMPING typo in iob_alloc 2026-09-19 16:36:47 -03:00
net net/pkt: remove unused variable conn in append_timestamping 2026-09-19 18:32:45 -03:00
openamp cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
pass1 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
sched sched/module: Increase /proc/modules line buffer. 2026-09-22 13:27:42 +08:00
syscall fs: add chroot() syscall 2026-09-20 22:27:38 +08:00
tools arch/arm/ameba: add GPIO driver for RTL8730E (AmebaSmart CA32) 2026-09-22 09:18:16 -03:00
video video/videomode: Fix EDID parsing and formatting of video mode dumps 2026-08-29 11:09:11 -03:00
wireless wireless/bluetooth: Validate the L2CAP header on the first ACL fragment. 2026-09-22 10:07:09 -03:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines arch/arm: Reserve r10 via ARCHCFLAGS and hoist the PIC module flags. 2026-07-24 23:09:08 +08:00
.codespellrc zbus: Add linker support and documentation for the zbus port 2026-09-21 08:40:14 -03:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore boards/risc-v/eic7700x: Adopt the common board layout. 2026-08-19 01:40:57 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml pre-commit: enable codespell checks 2025-05-05 12:34:39 +08:00
.yamllint feat: add a GitHub action to lint the YAML files 2020-12-15 09:52:04 -06:00
AUTHORS AUTHORS: add Jorge Guzman 2026-08-25 08:43:13 -04:00
CMakeLists.txt cmake: reconfigure when .config changes 2026-09-14 18:40:45 -03:00
CONTRIBUTING.md contributing: Add requirement for 'Assisted-by' commit field 2026-07-12 09:42:28 +08:00
INVIOLABLES.md INVIOLABLES.md: Fix a simple alignment and change occurrences of Nuttx 2020-09-03 01:33:05 +08:00
Kconfig include/nuttx: Add link-time iterable sections infrastructure 2026-08-27 01:04:05 +08:00
LICENSE libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-07-09 22:41:11 +08:00
NOTICE Remove the double blank line from source files 2022-02-20 20:10:14 +01:00
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes Documentation: move ReleaseNotes 2023-09-26 20:41:00 +08:00

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.