fix(nimble): Fix vulnerabilities in NimBLE examples

This commit is contained in:
Shreeyash
2026-02-06 18:47:08 +05:30
parent b9f2b4b547
commit 5319914af2
43 changed files with 902 additions and 316 deletions
+14 -3
View File
@@ -119,6 +119,10 @@ blecent_on_custom_write(uint16_t conn_handle,
error->status, conn_handle, attr->handle);
peer = peer_find(conn_handle);
if (peer == NULL) {
MODLOG_DFLT(WARN,"Peer not found (conn_handle=%d), likely disconnected\n",conn_handle);
return 0;
}
chr = peer_chr_find_uuid(peer,
remote_svc_uuid,
remote_chr_uuid);
@@ -255,6 +259,7 @@ blecent_on_subscribe(uint16_t conn_handle,
if (peer == NULL) {
MODLOG_DFLT(ERROR, "Error in finding peer, aborting...");
ble_gap_terminate(conn_handle, BLE_ERR_REM_USER_CONN_TERM);
return 0;
}
/* Subscribe to, write to, and read the custom characteristic*/
blecent_custom_gatt_operations(peer);
@@ -284,7 +289,10 @@ blecent_on_write(uint16_t conn_handle,
uint8_t value[2];
int rc;
const struct peer *peer = peer_find(conn_handle);
if (peer == NULL) {
MODLOG_DFLT(ERROR, "Error: peer not found for conn_handle=%d", conn_handle);
return ble_gap_terminate(conn_handle, BLE_ERR_REM_USER_CONN_TERM); // Use conn_handle to avoid dereference
}
dsc = peer_dsc_find_uuid(peer,
BLE_UUID16_DECLARE(BLECENT_SVC_ALERT_UUID),
BLE_UUID16_DECLARE(BLECENT_CHR_UNR_ALERT_STAT_UUID),
@@ -336,7 +344,10 @@ blecent_on_read(uint16_t conn_handle,
uint8_t value[2];
int rc;
const struct peer *peer = peer_find(conn_handle);
if (peer == NULL) {
MODLOG_DFLT(ERROR, "Error: peer not found for conn_handle=%d", conn_handle);
return ble_gap_terminate(conn_handle, BLE_ERR_REM_USER_CONN_TERM);
}
chr = peer_chr_find_uuid(peer,
BLE_UUID16_DECLARE(BLECENT_SVC_ALERT_UUID),
BLE_UUID16_DECLARE(BLECENT_CHR_ALERT_NOT_CTRL_PT));
@@ -875,7 +886,7 @@ blecent_gap_event(struct ble_gap_event *event, void *arg)
event->cache_assoc.status,
(event->cache_assoc.cache_state == 0) ? "INVALID" : "LOADED");
/* Perform service discovery */
rc = peer_disc_all(event->connect.conn_handle,
rc = peer_disc_all(event->cache_assoc.conn_handle,
blecent_on_disc_complete, NULL);
if(rc != 0) {
MODLOG_DFLT(ERROR, "Failed to discover services; rc=%d\n", rc);