mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(bt/bluedroid): fixed an OOB bug in btm_delete_stored_link_key_complete
This commit is contained in:
@@ -1203,7 +1203,7 @@ tBTM_STATUS BTM_DeleteStoredLinkKey(BD_ADDR bd_addr, tBTM_CMPL_CB *p_cb)
|
|||||||
** Returns void
|
** Returns void
|
||||||
**
|
**
|
||||||
*******************************************************************************/
|
*******************************************************************************/
|
||||||
void btm_delete_stored_link_key_complete (UINT8 *p)
|
void btm_delete_stored_link_key_complete (UINT8 *p, UINT16 evt_len)
|
||||||
{
|
{
|
||||||
tBTM_CMPL_CB *p_cb = btm_cb.devcb.p_stored_link_key_cmpl_cb;
|
tBTM_CMPL_CB *p_cb = btm_cb.devcb.p_stored_link_key_cmpl_cb;
|
||||||
tBTM_DELETE_STORED_LINK_KEY_COMPLETE result;
|
tBTM_DELETE_STORED_LINK_KEY_COMPLETE result;
|
||||||
@@ -1215,10 +1215,16 @@ void btm_delete_stored_link_key_complete (UINT8 *p)
|
|||||||
/* Set the call back event to indicate command complete */
|
/* Set the call back event to indicate command complete */
|
||||||
result.event = BTM_CB_EVT_DELETE_STORED_LINK_KEYS;
|
result.event = BTM_CB_EVT_DELETE_STORED_LINK_KEYS;
|
||||||
|
|
||||||
|
if (evt_len < 3) {
|
||||||
|
BTM_TRACE_ERROR("Malformatted event packet, too short");
|
||||||
|
result.status = BTM_ERR_PROCESSING;
|
||||||
|
goto err_out;
|
||||||
|
}
|
||||||
/* Extract the result fields from the HCI event */
|
/* Extract the result fields from the HCI event */
|
||||||
STREAM_TO_UINT8 (result.status, p);
|
STREAM_TO_UINT8 (result.status, p);
|
||||||
STREAM_TO_UINT16 (result.num_keys, p);
|
STREAM_TO_UINT16 (result.num_keys, p);
|
||||||
|
|
||||||
|
err_out:
|
||||||
/* Call the call back and pass the result */
|
/* Call the call back and pass the result */
|
||||||
(*p_cb)(&result);
|
(*p_cb)(&result);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1178,7 +1178,7 @@ void btm_vsc_complete (UINT8 *p, UINT16 cc_opcode, UINT16 evt_len,
|
|||||||
tBTM_CMPL_CB *p_vsc_cplt_cback);
|
tBTM_CMPL_CB *p_vsc_cplt_cback);
|
||||||
void btm_inq_db_reset (void);
|
void btm_inq_db_reset (void);
|
||||||
void btm_vendor_specific_evt (UINT8 *p, UINT8 evt_len);
|
void btm_vendor_specific_evt (UINT8 *p, UINT8 evt_len);
|
||||||
void btm_delete_stored_link_key_complete (UINT8 *p);
|
void btm_delete_stored_link_key_complete (UINT8 *p, UINT16 evt_len);
|
||||||
void btm_report_device_status (tBTM_DEV_STATUS status);
|
void btm_report_device_status (tBTM_DEV_STATUS status);
|
||||||
void btm_set_afh_channels_complete (UINT8 *p);
|
void btm_set_afh_channels_complete (UINT8 *p);
|
||||||
void btm_ble_set_channels_complete (UINT8 *p);
|
void btm_ble_set_channels_complete (UINT8 *p);
|
||||||
|
|||||||
@@ -1142,7 +1142,7 @@ static void btu_hcif_hdl_command_complete (UINT16 opcode, UINT8 *p, UINT16 evt_l
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case HCI_DELETE_STORED_LINK_KEY:
|
case HCI_DELETE_STORED_LINK_KEY:
|
||||||
btm_delete_stored_link_key_complete (p);
|
btm_delete_stored_link_key_complete (p, evt_len);
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case HCI_GET_LINK_QUALITY:
|
case HCI_GET_LINK_QUALITY:
|
||||||
|
|||||||
Reference in New Issue
Block a user