mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(ble/bluedroid): Fix potential out-of-bounds issue
- add length check in hci_hal_h4_hdl_rx_packet to prevent OOB
- add adv data length check in btm_ble_cache_adv_data
- add indicate data length check in BTA_GATTS_HandleValueIndication
- add report length check in bta_hh_parse_keybd_rpt
- add report length check in BTA_HdSendReport
- add descriptor length check in BTA_HdRegisterApp
- prevent buffer overflow in attribute processing
(cherry picked from commit 71efec78c5)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
This commit is contained in:
@@ -3113,6 +3113,13 @@ void btm_ble_cache_adv_data(BD_ADDR bda, tBTM_INQ_RESULTS *p_cur, UINT8 data_len
|
||||
p_cur->scan_rsp_len = 0;
|
||||
}
|
||||
|
||||
/* Additional validation to prevent potential integer overflow */
|
||||
if (data_len > BTM_BLE_CACHE_ADV_DATA_MAX) {
|
||||
BTM_TRACE_ERROR("BLE advertising data length exceeds maximum: %u > %u",
|
||||
data_len, BTM_BLE_CACHE_ADV_DATA_MAX);
|
||||
return;
|
||||
}
|
||||
|
||||
if (data_len > 0) {
|
||||
p_cache = &p_le_inq_cb->adv_data_cache[p_le_inq_cb->adv_len];
|
||||
if((data_len + p_le_inq_cb->adv_len) <= BTM_BLE_CACHE_ADV_DATA_MAX) {
|
||||
|
||||
Reference in New Issue
Block a user