nuttx/wireless
Alan Carvalho de Assis 9d12f6ccc6 wireless/bluetooth: Validate the L2CAP header on the first ACL fragment.
bt_conn_receive() read the 4-octet L2CAP header out of the first fragment
of a PDU without checking that 4 octets had been received, and then
computed the outstanding length by subtracting the fragment length from
the declared PDU length.

Two problems follow.  A fragment shorter than the header was parsed from
whatever happened to follow it in the buffer.  And a fragment carrying
more data than the PDU it declares made the subtraction wrap, because
conn->rx_len is 16 bits: the connection was then left expecting up to
65535 further octets, holding the partial PDU and accumulating later
fragments against an expectation that could never be satisfied.

Check that the fragment is long enough to hold a header before reading
it, and that it does not exceed the PDU it declares before computing what
remains.  Drop the fragment and reset the reassembly state otherwise.

Ref: Core v6.0, Vol 3, Part A, 3.1 (B-frame format)
Ref: Core v6.0, Vol 4, Part E, 5.4.2 (HCI ACL Data packets)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller adds the truncated and oversized fragment cases
separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-22 10:07:09 -03:00
..
bluetooth wireless/bluetooth: Validate the L2CAP header on the first ACL fragment. 2026-09-22 10:07:09 -03:00
ieee802154 drivers/: Multiple Drivers Are Registered With World Writable - Part 2 2026-07-15 15:27:28 +08:00
pktradio include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig
Makefile tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00