fix(nimble): Fix vulnerabilities in NimBLE examples

This commit is contained in:
Shreeyash
2026-03-10 14:46:05 +05:30
parent 5ecafbffc1
commit ea1a30b3ef
43 changed files with 875 additions and 303 deletions
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2021-2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Unlicense OR CC0-1.0
*/
@@ -103,7 +103,7 @@ char *CategoryID_to_String(uint8_t CategoryID)
void ble_receive_apple_notification_source(uint8_t *message, uint16_t message_len)
{
if (!message || message_len < 5) {
if (!message || message_len < 8) {
return;
}
@@ -126,14 +126,19 @@ void ble_receive_apple_data_source(uint8_t *message, uint16_t message_len)
switch (Command_id)
{
case CommandIDGetNotificationAttributes: {
if (message_len < 5) {
ESP_LOGE(NimBLE_ANCS_TAG, "Invalid message length for attributes: %d",
message_len);
return;
}
uint32_t NotificationUID = (message[1]) | (message[2]<< 8) | (message[3]<< 16) | (message[4] << 24);
uint32_t remian_attr_len = message_len - 5;
uint8_t *attrs = &message[5];
ESP_LOGI(NimBLE_ANCS_TAG, "recevice Notification Attributes response Command_id %d NotificationUID %" PRIu32, Command_id, NotificationUID);
while(remian_attr_len > 0) {
while(remian_attr_len >= 3) {
uint8_t AttributeID = attrs[0];
uint16_t len = attrs[1] | (attrs[2] << 8);
if(len > (remian_attr_len -3)) {
if(len > remian_attr_len - 3) {
ESP_LOGE(NimBLE_ANCS_TAG, "data error");
break;
}
+14 -9
View File
@@ -72,7 +72,7 @@ static uint8_t ext_adv_pattern_1[] = {
0x02, BLE_HS_ADV_TYPE_FLAGS, 0x06,
0x03, BLE_HS_ADV_TYPE_COMP_UUIDS16, 0xab, 0xcd,
0x03, BLE_HS_ADV_TYPE_COMP_UUIDS16, 0x18, 0x11,
0x0e, BLE_HS_ADV_TYPE_COMP_NAME, 'n', 'i', 'm', 'b', 'l', 'e', '-', 'a', 'n', 'c', 's', '-', 'e',
0x0d, BLE_HS_ADV_TYPE_COMP_NAME, 'n', 'i', 'm', 'b', 'l', 'e', '-', 'a', 'n', 'c', 's', '-', 'e',
};
#endif
@@ -338,14 +338,13 @@ ext_ble_ancs_advertise(void)
}
/* use defaults for non-set params */
memset (&params, 0, sizeof(params));
memset(&params, 0, sizeof(params));
/* enable connectable advertising */
params.connectable = 1;
/* advertise using random addr */
/* advertise using configured addr */
params.own_addr_type = BLE_OWN_ADDR_PUBLIC;
params.primary_phy = BLE_HCI_LE_PHY_1M;
params.secondary_phy = BLE_HCI_LE_PHY_2M;
params.tx_power = 127;
@@ -359,8 +358,6 @@ ext_ble_ancs_advertise(void)
ble_ancs_gap_event, NULL);
assert (rc == 0);
/* in this case only scan response is allowed */
/* get mbuf for scan rsp data */
data = os_msys_get_pkthdr(sizeof(ext_adv_pattern_1), 0);
assert(data);
@@ -578,10 +575,18 @@ ble_ancs_gap_event(struct ble_gap_event *event, void *arg)
notificationUID, sizeof(p_attr)/sizeof(ble_noti_attr_list_t), p_attr);
}
} else if (event->notify_rx.attr_handle == data_source_handle) {
uint16_t new_len = data_buffer.len + event->notify_rx.om->om_len;
if (new_len > sizeof(data_buffer.buffer)) {
MODLOG_DFLT(ERROR, "data_buffer overflow: %d + %d > %d",
data_buffer.len, event->notify_rx.om->om_len,
(int)sizeof(data_buffer.buffer));
data_buffer.len = 0;
return 0;
}
memcpy(&data_buffer.buffer[data_buffer.len],
event->notify_rx.om->om_data,
event->notify_rx.om->om_len);
data_buffer.len += event->notify_rx.om->om_len;
event->notify_rx.om->om_data,
event->notify_rx.om->om_len);
data_buffer.len = new_len;
if (event->notify_rx.om->om_len == (MTU_size - 3)) {
esp_timer_start_periodic(periodic_timer, 500000);