acassis opened a new pull request, #20243:
URL: https://github.com/apache/nuttx/pull/20243

   ## Summary
   The hci_event() consumed the event header and dispatched on the event code 
without checking that a header had been received, and hci_le_meta_event() did 
the same for the subevent code.  Each handler then cast the remaining buffer to 
its event structure and read fields out of it, so a short event was parsed from 
whatever followed it in memory - including the fields that identify a 
connection and carry its encryption state.
   
   Check that the header is present before reading it, that the parameters the 
event declares were actually received, and that enough parameters remain for 
the structure the selected handler casts to.  Events failing a check are 
dropped with a diagnostic rather than parsed.
   
   le_adv_report() continues to do its own checking, because the report count 
and the per-report lengths vary within that event.
   
   ## Impact
   
   Improvement
   
   ## Testing
   
   before:
   ```
   nsh> bt bnep0 scan start
   hci_event: event 62
   le_adv_report: Adv number of reports 1
   le_adv_report: 5A:05:D9:40:02:CC (public) event 0, len 28, rssi -69 dBm
   hci_event: event 62
   le_adv_report: Adv number of reports 1
   le_adv_report: 5A:05:D9:40:02:CC (public) event 4, len 14, rssi -70 dBm
   ...
   ```
   - LE Meta Events dispatched: **108**
   - Advertising reports parsed: **108**
   - Length-guard messages: **0** — the guard code does not exist in this build.
   
   after:
   ```
   nsh> bt bnep0 scan start
   hci_event: event 62
   le_adv_report: Adv number of reports 1
   le_adv_report: 5A:05:D9:40:02:CC (public) event 0, len 28, rssi -70 dBm
   hci_event: event 62
   le_adv_report: Adv number of reports 1
   le_adv_report: 5A:05:D9:40:02:CC (public) event 4, len 14, rssi -71 dBm
   ...
   ```
   
   - LE Meta Events dispatched: **85** (a different scan window; not 
significant)
   - Advertising reports parsed: **85**
   - **Valid events wrongly rejected by the new guard: 0.**
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to