This is an automated email from the ASF dual-hosted git repository.
jerpelea pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git
The following commit(s) were added to refs/heads/master by this push:
new 843cf6d5819 wireless/bluetooth: Validate Number Of Completed Packets
event.
843cf6d5819 is described below
commit 843cf6d581981ed870ce5a1279c3fac2571c4947
Author: Alan Carvalho de Assis <[email protected]>
AuthorDate: Thu Sep 17 10:20:37 2026 -0300
wireless/bluetooth: Validate Number Of Completed Packets event.
Two problems in hci_num_completed_packets().
Number_of_Handles is a single octet, but it was read with BT_LE162HOST(),
which takes the first octet of the handle that follows it as the high
byte. A one-octet field could therefore produce a loop count of up to
65535.
The loop was then bounded only by that count and not by the data that was
actually received, so it walked past the end of the event, reading handle
and count pairs out of whatever followed it.
Read the field at its declared width, and require the pairs the event
claims to have been received before reading them.
Per-connection credit accounting, which this handler still does not do,
is a separate change.
Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.
Signed-off-by: Alan C. Assis <[email protected]>
Assisted-by: Claude Code Opus 5
---
wireless/bluetooth/bt_hcicore.c | 28 ++++++++++++++++++++++++++--
1 file changed, 26 insertions(+), 2 deletions(-)
diff --git a/wireless/bluetooth/bt_hcicore.c b/wireless/bluetooth/bt_hcicore.c
index 8705a08fae6..cf8625d80e3 100644
--- a/wireless/bluetooth/bt_hcicore.c
+++ b/wireless/bluetooth/bt_hcicore.c
@@ -432,8 +432,32 @@ static void hci_cmd_status(FAR struct bt_buf_s *buf)
static void hci_num_completed_packets(FAR struct bt_buf_s *buf)
{
FAR struct bt_hci_evt_num_completed_packets_s *evt = (FAR void *)buf->data;
- uint16_t num_handles = BT_LE162HOST(evt->num_handles);
- uint16_t i;
+ uint8_t num_handles;
+ uint8_t i;
+
+ if (buf->len < sizeof(*evt))
+ {
+ wlerr("ERROR: Truncated Number Of Completed Packets event\n");
+ return;
+ }
+
+ /* Number_of_Handles is one octet. Reading it with BT_LE162HOST() took
+ * the first octet of the following handle as its high byte, so a count
+ * of up to 65535 could be produced from a one-octet field.
+ */
+
+ num_handles = evt->num_handles;
+
+ /* The handle and count pairs the event declares have to have been
+ * received before they can be read.
+ */
+
+ if (buf->len < sizeof(*evt) + num_handles * sizeof(evt->h[0]))
+ {
+ wlerr("ERROR: Event declares %u handles but carries %u octets\n",
+ num_handles, buf->len);
+ return;
+ }
wlinfo("num_handles %u\n", num_handles);