fix(nimble): Fix vulnerabilities in NimBLE examples

This commit is contained in:
Shreeyash
2026-02-06 18:47:08 +05:30
parent b9f2b4b547
commit 5319914af2
43 changed files with 902 additions and 316 deletions
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2021-2022 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Unlicense OR CC0-1.0
*/
@@ -69,22 +69,26 @@ gatt_svr_chr_access_le_phy(uint16_t conn_handle, uint16_t attr_handle,
case BLE_GATT_ACCESS_OP_WRITE_CHR:
len = OS_MBUF_PKTLEN(ctxt->om);
if (len > 0) {
le_phy_val = (uint8_t *)malloc(len * sizeof(uint8_t));
if (le_phy_val) {
rc = ble_hs_mbuf_to_flat(ctxt->om, le_phy_val, len, &copied_len);
if (rc == 0) {
MODLOG_DFLT(INFO, "Write received of len = %d", copied_len);
return 0;
} else {
MODLOG_DFLT(ERROR, "Failed to receive write characteristic");
}
}
if (len == 0) {
return BLE_ATT_ERR_INVALID_ATTR_VALUE_LEN;
}
break;
le_phy_val = (uint8_t *)malloc(len);
if (le_phy_val == NULL) {
return BLE_ATT_ERR_INSUFFICIENT_RES;
}
rc = ble_hs_mbuf_to_flat(ctxt->om, le_phy_val, len, &copied_len);
free(le_phy_val);
if (rc == 0) {
MODLOG_DFLT(INFO, "Write received of len = %d", (int)copied_len);
return 0;
}
MODLOG_DFLT(ERROR, "Failed to receive write characteristic");
return BLE_ATT_ERR_INSUFFICIENT_RES;
default:
break;
return BLE_ATT_ERR_UNLIKELY;
}
}