mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(nimble): Fix vulnerabilities in NimBLE examples
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2021-2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Unlicense OR CC0-1.0
|
||||
*/
|
||||
@@ -103,7 +103,7 @@ char *CategoryID_to_String(uint8_t CategoryID)
|
||||
|
||||
void ble_receive_apple_notification_source(uint8_t *message, uint16_t message_len)
|
||||
{
|
||||
if (!message || message_len < 5) {
|
||||
if (!message || message_len < 8) {
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -126,14 +126,19 @@ void ble_receive_apple_data_source(uint8_t *message, uint16_t message_len)
|
||||
switch (Command_id)
|
||||
{
|
||||
case CommandIDGetNotificationAttributes: {
|
||||
if (message_len < 5) {
|
||||
ESP_LOGE(NimBLE_ANCS_TAG, "Invalid message length for attributes: %d",
|
||||
message_len);
|
||||
return;
|
||||
}
|
||||
uint32_t NotificationUID = (message[1]) | (message[2]<< 8) | (message[3]<< 16) | (message[4] << 24);
|
||||
uint32_t remian_attr_len = message_len - 5;
|
||||
uint8_t *attrs = &message[5];
|
||||
ESP_LOGI(NimBLE_ANCS_TAG, "recevice Notification Attributes response Command_id %d NotificationUID %" PRIu32, Command_id, NotificationUID);
|
||||
while(remian_attr_len > 0) {
|
||||
while(remian_attr_len >= 3) {
|
||||
uint8_t AttributeID = attrs[0];
|
||||
uint16_t len = attrs[1] | (attrs[2] << 8);
|
||||
if(len > (remian_attr_len -3)) {
|
||||
if(len > remian_attr_len - 3) {
|
||||
ESP_LOGE(NimBLE_ANCS_TAG, "data error");
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -72,7 +72,7 @@ static uint8_t ext_adv_pattern_1[] = {
|
||||
0x02, BLE_HS_ADV_TYPE_FLAGS, 0x06,
|
||||
0x03, BLE_HS_ADV_TYPE_COMP_UUIDS16, 0xab, 0xcd,
|
||||
0x03, BLE_HS_ADV_TYPE_COMP_UUIDS16, 0x18, 0x11,
|
||||
0x0e, BLE_HS_ADV_TYPE_COMP_NAME, 'n', 'i', 'm', 'b', 'l', 'e', '-', 'a', 'n', 'c', 's', '-', 'e',
|
||||
0x0d, BLE_HS_ADV_TYPE_COMP_NAME, 'n', 'i', 'm', 'b', 'l', 'e', '-', 'a', 'n', 'c', 's', '-', 'e',
|
||||
};
|
||||
#endif
|
||||
|
||||
@@ -338,14 +338,13 @@ ext_ble_ancs_advertise(void)
|
||||
}
|
||||
|
||||
/* use defaults for non-set params */
|
||||
memset (¶ms, 0, sizeof(params));
|
||||
memset(¶ms, 0, sizeof(params));
|
||||
|
||||
/* enable connectable advertising */
|
||||
params.connectable = 1;
|
||||
|
||||
/* advertise using random addr */
|
||||
/* advertise using configured addr */
|
||||
params.own_addr_type = BLE_OWN_ADDR_PUBLIC;
|
||||
|
||||
params.primary_phy = BLE_HCI_LE_PHY_1M;
|
||||
params.secondary_phy = BLE_HCI_LE_PHY_2M;
|
||||
params.tx_power = 127;
|
||||
@@ -359,8 +358,6 @@ ext_ble_ancs_advertise(void)
|
||||
ble_ancs_gap_event, NULL);
|
||||
assert (rc == 0);
|
||||
|
||||
/* in this case only scan response is allowed */
|
||||
|
||||
/* get mbuf for scan rsp data */
|
||||
data = os_msys_get_pkthdr(sizeof(ext_adv_pattern_1), 0);
|
||||
assert(data);
|
||||
@@ -578,10 +575,18 @@ ble_ancs_gap_event(struct ble_gap_event *event, void *arg)
|
||||
notificationUID, sizeof(p_attr)/sizeof(ble_noti_attr_list_t), p_attr);
|
||||
}
|
||||
} else if (event->notify_rx.attr_handle == data_source_handle) {
|
||||
uint16_t new_len = data_buffer.len + event->notify_rx.om->om_len;
|
||||
if (new_len > sizeof(data_buffer.buffer)) {
|
||||
MODLOG_DFLT(ERROR, "data_buffer overflow: %d + %d > %d",
|
||||
data_buffer.len, event->notify_rx.om->om_len,
|
||||
(int)sizeof(data_buffer.buffer));
|
||||
data_buffer.len = 0;
|
||||
return 0;
|
||||
}
|
||||
memcpy(&data_buffer.buffer[data_buffer.len],
|
||||
event->notify_rx.om->om_data,
|
||||
event->notify_rx.om->om_len);
|
||||
data_buffer.len += event->notify_rx.om->om_len;
|
||||
event->notify_rx.om->om_data,
|
||||
event->notify_rx.om->om_len);
|
||||
data_buffer.len = new_len;
|
||||
|
||||
if (event->notify_rx.om->om_len == (MTU_size - 3)) {
|
||||
esp_timer_start_periodic(periodic_timer, 500000);
|
||||
|
||||
Reference in New Issue
Block a user