mirror of
https://github.com/apache/nuttx.git
synced 2026-10-02 11:48:02 +00:00
bt_conn_receive() read the 4-octet L2CAP header out of the first fragment of a PDU without checking that 4 octets had been received, and then computed the outstanding length by subtracting the fragment length from the declared PDU length. Two problems follow. A fragment shorter than the header was parsed from whatever happened to follow it in the buffer. And a fragment carrying more data than the PDU it declares made the subtraction wrap, because conn->rx_len is 16 bits: the connection was then left expecting up to 65535 further octets, holding the partial PDU and accumulating later fragments against an expectation that could never be satisfied. Check that the fragment is long enough to hold a header before reading it, and that it does not exceed the PDU it declares before computing what remains. Drop the fragment and reset the reassembly state otherwise. Ref: Core v6.0, Vol 3, Part A, 3.1 (B-frame format) Ref: Core v6.0, Vol 4, Part E, 5.4.2 (HCI ACL Data packets) Testing: builds for sim:bluetooth with Make; every commit in this series verified to build individually. Not yet exercised at runtime - the scriptable controller adds the truncated and oversized fragment cases separately. Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5 |
||
|---|---|---|
| .. | ||
| bluetooth | ||
| ieee802154 | ||
| pktradio | ||
| CMakeLists.txt | ||
| Kconfig | ||
| Makefile | ||