nuttx/wireless
Alan Carvalho de Assis 5ec51ae6d5 wireless/bluetooth: Validate lengths when parsing advertising reports.
le_adv_report() took the report count and each report's data length from
the event and used them without checking either against the data that was
actually received:

  - the declared data length indexes the RSSI octet, so a length larger
    than the event reads past the end of the buffer;
  - the loop was bounded only by the report count, so a count larger than
    the payload walks off the end of it;
  - bt_buf_consume() only checks its bound with DEBUGASSERT(), so on a
    build without assertions the buffer length underflows rather than
    reporting the problem.

Check that the event is long enough for the count, then check each report
against the remaining length before reading its data or its RSSI, and
stop parsing when a report does not fit.

While here, include the RSSI octet when advancing to the next report.
sizeof() of the report structure does not account for it, because the
data member is a zero-length array, so every report after the first
started one octet early.

Ref: Core v6.0, Vol 4, Part E, 7.7.65.2 (LE Advertising Report event)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller that can inject a malformed report is added
separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-19 18:30:43 -03:00
..
bluetooth wireless/bluetooth: Validate lengths when parsing advertising reports. 2026-09-19 18:30:43 -03:00
ieee802154 drivers/: Multiple Drivers Are Registered With World Writable - Part 2 2026-07-15 15:27:28 +08:00
pktradio include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig
Makefile tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00