mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(bt): fix BLE security issue in controller and HCI packet parser
(cherry picked from commit a721e94a0f)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
This commit is contained in:
committed by
zhanghaipeng
parent
4b4e0427f9
commit
86153bc133
@@ -87,7 +87,7 @@ typedef struct {
|
|||||||
uint16_t ble_ext_adv_data_max_len;
|
uint16_t ble_ext_adv_data_max_len;
|
||||||
#endif // #if (BLE_50_EXTEND_ADV_EN == TRUE)
|
#endif // #if (BLE_50_EXTEND_ADV_EN == TRUE)
|
||||||
#if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
#if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
||||||
uint16_t get_ble_periodic_advertiser_list_size;
|
uint8_t get_ble_periodic_advertiser_list_size;
|
||||||
#endif // #if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
#endif // #if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
||||||
#endif //#if (BLE_50_FEATURE_SUPPORT == TRUE)
|
#endif //#if (BLE_50_FEATURE_SUPPORT == TRUE)
|
||||||
} controller_local_param_t;
|
} controller_local_param_t;
|
||||||
|
|||||||
@@ -219,7 +219,7 @@ static void parse_ble_read_suggested_default_data_length_response(
|
|||||||
uint16_t *ble_default_packet_txtime_ptr)
|
uint16_t *ble_default_packet_txtime_ptr)
|
||||||
{
|
{
|
||||||
|
|
||||||
uint8_t *stream = read_command_complete_header(response, HCI_BLE_READ_DEFAULT_DATA_LENGTH, 2 /* bytes after */);
|
uint8_t *stream = read_command_complete_header(response, HCI_BLE_READ_DEFAULT_DATA_LENGTH, 4 /* bytes after: 2+2 */);
|
||||||
if (stream) {
|
if (stream) {
|
||||||
STREAM_TO_UINT16(*ble_default_packet_length_ptr, stream);
|
STREAM_TO_UINT16(*ble_default_packet_length_ptr, stream);
|
||||||
STREAM_TO_UINT16(*ble_default_packet_txtime_ptr, stream);
|
STREAM_TO_UINT16(*ble_default_packet_txtime_ptr, stream);
|
||||||
@@ -235,7 +235,7 @@ static void parse_ble_read_adv_max_len_response(
|
|||||||
uint16_t *adv_max_len_ptr)
|
uint16_t *adv_max_len_ptr)
|
||||||
{
|
{
|
||||||
|
|
||||||
uint8_t *stream = read_command_complete_header(response, HCI_BLE_RD_MAX_ADV_DATA_LEN, 1 /* bytes after */);
|
uint8_t *stream = read_command_complete_header(response, HCI_BLE_RD_MAX_ADV_DATA_LEN, 2 /* bytes after */);
|
||||||
if (stream) {
|
if (stream) {
|
||||||
// Size: 2 Octets ; Value: 0x001F – 0x0672 ; Maximum supported advertising data length
|
// Size: 2 Octets ; Value: 0x001F – 0x0672 ; Maximum supported advertising data length
|
||||||
STREAM_TO_UINT16(*adv_max_len_ptr, stream);
|
STREAM_TO_UINT16(*adv_max_len_ptr, stream);
|
||||||
@@ -246,7 +246,7 @@ static void parse_ble_read_adv_max_len_response(
|
|||||||
#if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
#if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
||||||
static void parse_ble_read_periodic_adv_list_size_response(
|
static void parse_ble_read_periodic_adv_list_size_response(
|
||||||
BT_HDR *response,
|
BT_HDR *response,
|
||||||
uint16_t *periodic_adv_list_size_ptr)
|
uint8_t *periodic_adv_list_size_ptr)
|
||||||
{
|
{
|
||||||
|
|
||||||
uint8_t *stream = read_command_complete_header(response, HCI_BLE_RD_PERIOD_ADV_LIST_SIZE, 1 /* bytes after */);
|
uint8_t *stream = read_command_complete_header(response, HCI_BLE_RD_PERIOD_ADV_LIST_SIZE, 1 /* bytes after */);
|
||||||
|
|||||||
@@ -114,7 +114,7 @@ typedef struct {
|
|||||||
#if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
#if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
||||||
void (*parse_ble_read_periodic_adv_list_size_response) (
|
void (*parse_ble_read_periodic_adv_list_size_response) (
|
||||||
BT_HDR *response,
|
BT_HDR *response,
|
||||||
uint16_t *periodic_advertiser_list_size
|
uint8_t *periodic_advertiser_list_size
|
||||||
);
|
);
|
||||||
#endif // #if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
#endif // #if (BLE_50_EXTEND_SYNC_EN == TRUE)
|
||||||
#endif // #if (BLE_50_FEATURE_SUPPORT == TRUE)
|
#endif // #if (BLE_50_FEATURE_SUPPORT == TRUE)
|
||||||
|
|||||||
Reference in New Issue
Block a user