fix(nimble): Fix vulnerabilities in NimBLE examples

This commit is contained in:
Shreeyash
2026-02-06 18:43:33 +05:30
parent 5adf717cfd
commit dacec1afa1
43 changed files with 893 additions and 316 deletions
@@ -162,6 +162,10 @@ ble_htp_cent_on_read(uint16_t conn_handle,
uint16_t value;
int rc;
const struct peer *peer = peer_find(conn_handle);
if (peer == NULL) {
MODLOG_DFLT(ERROR, "Lost peer for conn_handle=%d\n", conn_handle);
return ble_gap_terminate(conn_handle, BLE_ERR_REM_USER_CONN_TERM);
}
chr = peer_chr_find_uuid(peer,
BLE_UUID16_DECLARE(BLE_SVC_HTP_UUID16),
@@ -330,7 +334,7 @@ ext_ble_htp_cent_should_connect(const struct ble_gap_ext_disc_desc *disc)
/* Conversion */
for (int i=0; i<6; i++) {
test_addr[i] = (uint8_t )peer_addr[i];
test_addr[i] = (uint8_t )peer_addr[5 - i];
}
if (memcmp(test_addr, disc->addr.val, sizeof(disc->addr.val)) != 0) {
@@ -341,23 +345,23 @@ ext_ble_htp_cent_should_connect(const struct ble_gap_ext_disc_desc *disc)
/* The device has to advertise support for the Health thermometer
* service (0x1809).
*/
do {
while (offset < disc->length_data) {
ad_struct_len = disc->data[offset];
if (!ad_struct_len) {
if (ad_struct_len == 0 || offset + ad_struct_len + 1 > disc->length_data) {
break;
}
/* Search if HTP UUID is advertised */
if (disc->data[offset] == 0x03 && disc->data[offset + 1] == 0x03) {
if ( disc->data[offset + 2] == 0x18 && disc->data[offset + 3] == 0x09 ) {
if (disc->data[offset + 1] == 0x03) {
if (disc->data[offset + 2] == 0x09 && disc->data[offset + 3] == 0x18) {
return 1;
}
}
offset += ad_struct_len + 1;
} while ( offset < disc->length_data );
}
return 0;
}
@@ -605,7 +609,7 @@ ble_htp_cent_gap_event(struct ble_gap_event *event, void *arg)
#else
#if MYNEWT_VAL(BLE_GATTC)
/*** Go for service discovery after encryption has been successfully enabled ***/
rc = peer_disc_all(event->connect.conn_handle,
rc = peer_disc_all(event->enc_change.conn_handle,
ble_htp_cent_on_disc_complete, NULL);
if (rc != 0) {
MODLOG_DFLT(ERROR, "Failed to discover services; rc=%d\n", rc);
@@ -624,7 +628,7 @@ ble_htp_cent_gap_event(struct ble_gap_event *event, void *arg)
event->cache_assoc.status,
(event->cache_assoc.cache_state == 0) ? "INVALID" : "LOADED");
/* Perform service discovery */
rc = peer_disc_all(event->connect.conn_handle,
rc = peer_disc_all(event->cache_assoc.conn_handle,
blecent_on_disc_complete, NULL);
if(rc != 0) {
MODLOG_DFLT(ERROR, "Failed to discover services; rc=%d\n", rc);