fix(ble/bluedroid): Fix security issues in HCI module

(cherry picked from commit b163685c06)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
This commit is contained in:
Zhang Hai Peng
2025-12-03 11:54:23 +08:00
parent 7c7f30aa09
commit ef96110b4d
2 changed files with 9 additions and 5 deletions
+8 -4
View File
@@ -452,10 +452,12 @@ static bool filter_incoming_event(BT_HDR *packet)
STREAM_TO_UINT8(hci_host_env.command_credits, stream); STREAM_TO_UINT8(hci_host_env.command_credits, stream);
STREAM_TO_UINT16(opcode, stream); STREAM_TO_UINT16(opcode, stream);
wait_entry = get_waiting_command(opcode); wait_entry = get_waiting_command(opcode);
metadata = (hci_cmd_metadata_t *)(wait_entry->data);
if (!wait_entry) { if (!wait_entry) {
HCI_TRACE_WARNING("%s command complete event with no matching command. opcode: 0x%x.", __func__, opcode); HCI_TRACE_WARNING("%s command complete event with no matching command. opcode: 0x%x.", __func__, opcode);
} else if (metadata->command_complete_cb) { goto intercepted;
}
metadata = (hci_cmd_metadata_t *)(wait_entry->data);
if (metadata->command_complete_cb) {
metadata->command_complete_cb(packet, metadata->context); metadata->command_complete_cb(packet, metadata->context);
#if (BLE_50_FEATURE_SUPPORT == TRUE) #if (BLE_50_FEATURE_SUPPORT == TRUE)
BlE_SYNC *sync_info = btsnd_hcic_ble_get_sync_info(); BlE_SYNC *sync_info = btsnd_hcic_ble_get_sync_info();
@@ -482,10 +484,12 @@ static bool filter_incoming_event(BT_HDR *packet)
// If a command generates a command status event, it won't be getting a command complete event // If a command generates a command status event, it won't be getting a command complete event
wait_entry = get_waiting_command(opcode); wait_entry = get_waiting_command(opcode);
metadata = (hci_cmd_metadata_t *)(wait_entry->data);
if (!wait_entry) { if (!wait_entry) {
HCI_TRACE_WARNING("%s command status event with no matching command. opcode: 0x%x", __func__, opcode); HCI_TRACE_WARNING("%s command status event with no matching command. opcode: 0x%x", __func__, opcode);
} else if (metadata->command_status_cb) { goto intercepted;
}
metadata = (hci_cmd_metadata_t *)(wait_entry->data);
if (metadata->command_status_cb) {
metadata->command_status_cb(status, &metadata->command, metadata->context); metadata->command_status_cb(status, &metadata->command, metadata->context);
} }
@@ -164,7 +164,7 @@ static void parse_ble_read_buffer_size_response_v2 (
uint8_t *iso_pkt_num_ptr) uint8_t *iso_pkt_num_ptr)
{ {
uint8_t *stream = read_command_complete_header(response, HCI_BLE_READ_BUFFER_SZIE_V2, 3 /* bytes after */); uint8_t *stream = read_command_complete_header(response, HCI_BLE_READ_BUFFER_SZIE_V2, 6 /* bytes after: 2+1+2+1 */);
assert(stream != NULL); assert(stream != NULL);
STREAM_TO_UINT16(*data_size_ptr, stream); STREAM_TO_UINT16(*data_size_ptr, stream);
STREAM_TO_UINT8(*acl_buffer_count_ptr, stream); STREAM_TO_UINT8(*acl_buffer_count_ptr, stream);