From bfc62578dec68e7fe23b873353b2223775ad0a04 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Thu, 26 Mar 2026 11:11:08 +0800 Subject: [PATCH] fix(wifi_provisioning): fixes potential null dereference on malformed packet --- .../wifi_provisioning/src/wifi_config.c | 26 +++++++------- components/wifi_provisioning/src/wifi_scan.c | 35 ++++++++++++------- 2 files changed, 35 insertions(+), 26 deletions(-) diff --git a/components/wifi_provisioning/src/wifi_config.c b/components/wifi_provisioning/src/wifi_config.c index 1075a318089..b93723af52f 100644 --- a/components/wifi_provisioning/src/wifi_config.c +++ b/components/wifi_provisioning/src/wifi_config.c @@ -1,16 +1,8 @@ -// Copyright 2018 Espressif Systems (Shanghai) PTE LTD -// -// Licensed under the Apache License, Version 2.0 (the "License"); -// you may not use this file except in compliance with the License. -// You may obtain a copy of the License at -// -// http://www.apache.org/licenses/LICENSE-2.0 -// -// Unless required by applicable law or agreed to in writing, software -// distributed under the License is distributed on an "AS IS" BASIS, -// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -// See the License for the specific language governing permissions and -// limitations under the License. +/* + * SPDX-FileCopyrightText: 2018-2026 Espressif Systems (Shanghai) CO LTD + * + * SPDX-License-Identifier: Apache-2.0 + */ #include #include @@ -150,6 +142,14 @@ static esp_err_t cmd_set_config_handler(WiFiConfigPayload *req, } resp_set_config__init(resp_payload); + if (req->payload_case != WI_FI_CONFIG_PAYLOAD__PAYLOAD_CMD_SET_CONFIG || !req->cmd_set_config) { + ESP_LOGE(TAG, "Invalid set config command"); + resp_payload->status = STATUS__InvalidArgument; + resp->payload_case = WI_FI_CONFIG_PAYLOAD__PAYLOAD_RESP_SET_CONFIG; + resp->resp_set_config = resp_payload; + return ESP_OK; + } + wifi_prov_config_set_data_t req_data; memset(&req_data, 0, sizeof(req_data)); diff --git a/components/wifi_provisioning/src/wifi_scan.c b/components/wifi_provisioning/src/wifi_scan.c index bfc0596f521..356bb8dd6fb 100644 --- a/components/wifi_provisioning/src/wifi_scan.c +++ b/components/wifi_provisioning/src/wifi_scan.c @@ -1,16 +1,8 @@ -// Copyright 2019 Espressif Systems (Shanghai) PTE LTD -// -// Licensed under the Apache License, Version 2.0 (the "License"); -// you may not use this file except in compliance with the License. -// You may obtain a copy of the License at -// -// http://www.apache.org/licenses/LICENSE-2.0 -// -// Unless required by applicable law or agreed to in writing, software -// distributed under the License is distributed on an "AS IS" BASIS, -// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -// See the License for the specific language governing permissions and -// limitations under the License. +/* + * SPDX-FileCopyrightText: 2019-2026 Espressif Systems (Shanghai) CO LTD + * + * SPDX-License-Identifier: Apache-2.0 + */ #include #include @@ -73,6 +65,15 @@ static esp_err_t cmd_scan_start_handler(WiFiScanPayload *req, } resp_scan_start__init(resp_payload); + + if (req->payload_case != WI_FI_SCAN_PAYLOAD__PAYLOAD_CMD_SCAN_START || !req->cmd_scan_start) { + ESP_LOGE(TAG, "Invalid scan start command"); + resp->status = STATUS__InvalidArgument; + resp->payload_case = WI_FI_SCAN_PAYLOAD__PAYLOAD_RESP_SCAN_START; + resp->resp_scan_start = resp_payload; + return ESP_OK; + } + resp->status = (h->scan_start(req->cmd_scan_start->blocking, req->cmd_scan_start->passive, req->cmd_scan_start->group_channels, @@ -131,6 +132,14 @@ static esp_err_t cmd_scan_result_handler(WiFiScanPayload *req, } resp_scan_result__init(resp_payload); + if (req->payload_case != WI_FI_SCAN_PAYLOAD__PAYLOAD_CMD_SCAN_RESULT || !req->cmd_scan_result) { + ESP_LOGE(TAG, "Invalid scan result command"); + resp->status = STATUS__InvalidArgument; + resp->payload_case = WI_FI_SCAN_PAYLOAD__PAYLOAD_RESP_SCAN_RESULT; + resp->resp_scan_result = resp_payload; + return ESP_OK; + } + resp->status = STATUS__Success; resp->payload_case = WI_FI_SCAN_PAYLOAD__PAYLOAD_RESP_SCAN_RESULT; resp->resp_scan_result = resp_payload;