mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(ble/bluedroid): Fix double-free, exec write, bounds and HCI param checks
- gap_ble: add length/attribute checks in gap_proc_write_req - gatt_cl: set p_cmd->p_cmd=NULL before memset to avoid double-free; pending_cl_req %= GATT_CL_MAX_LCB - gatt_sr: fix exec write zeroed_attrs and offset/len bounds, OOM cleanup - gatt_sr_hash: null checks for p_attr->p_next, p_data+=2, len==0 in gatts_calculate_datebase_hash, gatts_show_local_database - gatt_utils: explicit return NULL, indent, idx<GATT_MAX_APPS checks, len>GATT_MAX_ATTR_LEN, gatt_cleanup_upon_disc dealloc branch - hciblecmds: length/handle validation in BLE ext adv/BIG sync HCI commands
This commit is contained in:
@@ -315,6 +315,9 @@ UINT8 gap_proc_write_req( tGATTS_REQ_TYPE type, tGATT_WRITE_REQ *p_data)
|
||||
switch (p_db_attr->uuid) {
|
||||
#if (GATTS_DEVICE_NAME_WRITABLE == TRUE)
|
||||
case GATT_UUID_GAP_DEVICE_NAME: {
|
||||
if (p_data->len > BD_NAME_LEN) {
|
||||
return GATT_INVALID_ATTR_LEN;
|
||||
}
|
||||
UINT8 *p_val = p_data->value;
|
||||
p_val[p_data->len] = '\0';
|
||||
BTM_SetLocalDeviceName((char *)p_val, BT_DEVICE_TYPE_BLE);
|
||||
|
||||
Reference in New Issue
Block a user