From caf9a41581f2f35efbfc5f2c245c5d90b4edd67c Mon Sep 17 00:00:00 2001 From: Linyan Liu Date: Tue, 30 Jun 2026 11:45:14 +0800 Subject: [PATCH] fix(ble_iso): Fix ISO SDU header pulled without minimum length check --- components/bt/esp_ble_iso/host/iso/iso.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/components/bt/esp_ble_iso/host/iso/iso.c b/components/bt/esp_ble_iso/host/iso/iso.c index d63e846376e..abdeb34bdf2 100644 --- a/components/bt/esp_ble_iso/host/iso/iso.c +++ b/components/bt/esp_ble_iso/host/iso/iso.c @@ -624,6 +624,17 @@ void bt_iso_recv(struct bt_conn *iso, struct net_buf *buf, uint8_t flags) case BT_ISO_SINGLE: iso_info.flags = 0; + /* A malformed ISO packet whose ISO_Data_Load_Length is below the SDU + * header size would underflow buf->len in net_buf_pull_mem (the guard + * assert is compiled out in release) and leak OOB bytes into the recv + * callback. Drop it before pulling the header. + */ + if (buf->len < (ts ? sizeof(struct bt_hci_iso_sdu_ts_hdr) + : sizeof(struct bt_hci_iso_sdu_hdr))) { + LOG_ERR("ShortIsoSduHdr[%u][%u]", buf->len, ts); + return; + } + /* The ISO_Data_Load field contains either the first fragment * of an SDU or a complete SDU. */