• R/O
  • HTTP
  • SSH
  • HTTPS

Commit

Tags
No Tags

Frequently used words (click to add to your profile)

javac++androidlinuxc#windowsobjective-ccocoa誰得qtpythonphprubygameguibathyscaphec計画中(planning stage)翻訳omegatframeworktwitterdomtestvb.netdirectxゲームエンジンbtronarduinopreviewer

system/bt


Commit MetaInfo

Revision5996428f328f390a3cd9cb67a114f031c5541f75 (tree)
Time2019-12-17 05:38:44
AuthorTed Wang <tedwang@goog...>
CommiterManjae Park

Log Message

Fix potential OOB write in btm_read_remote_ext_features_complete

Add event length check to avoid hci event sent from controller not
correct.
Add page number check to avoid page number is bigger than
HCI_EXT_FEATURES_PAGE_MAX.

Bug: 141552859
Bug: 144205318
Test: inject function
Merged-In: Iaca4db4ee9bf27362f62aba0da088727e98955d1
Change-Id: Iaca4db4ee9bf27362f62aba0da088727e98955d1
(cherry picked from commit 6dfae174853e0c49f36362e59a2c7ca607f01cf9)

Change Summary

Incremental Difference

--- a/stack/btm/btm_acl.cc
+++ b/stack/btm/btm_acl.cc
@@ -47,6 +47,7 @@
4747 #include "device/include/interop.h"
4848 #include "hcidefs.h"
4949 #include "hcimsgs.h"
50+#include "log/log.h"
5051 #include "l2c_int.h"
5152 #include "osi/include/osi.h"
5253
@@ -1062,7 +1063,7 @@ void btm_read_remote_features_complete(uint8_t* p) {
10621063 * Returns void
10631064 *
10641065 ******************************************************************************/
1065-void btm_read_remote_ext_features_complete(uint8_t* p) {
1066+void btm_read_remote_ext_features_complete(uint8_t* p, uint8_t evt_len) {
10661067 tACL_CONN* p_acl_cb;
10671068 uint8_t page_num, max_page;
10681069 uint16_t handle;
@@ -1070,6 +1071,14 @@ void btm_read_remote_ext_features_complete(uint8_t* p) {
10701071
10711072 BTM_TRACE_DEBUG("btm_read_remote_ext_features_complete");
10721073
1074+ if (evt_len < HCI_EXT_FEATURES_SUCCESS_EVT_LEN) {
1075+ android_errorWriteLog(0x534e4554, "141552859");
1076+ BTM_TRACE_ERROR(
1077+ "btm_read_remote_ext_features_complete evt length too short. length=%d",
1078+ evt_len);
1079+ return;
1080+ }
1081+
10731082 ++p;
10741083 STREAM_TO_UINT16(handle, p);
10751084 STREAM_TO_UINT8(page_num, p);
@@ -1089,6 +1098,19 @@ void btm_read_remote_ext_features_complete(uint8_t* p) {
10891098 return;
10901099 }
10911100
1101+ if (page_num > HCI_EXT_FEATURES_PAGE_MAX) {
1102+ android_errorWriteLog(0x534e4554, "141552859");
1103+ BTM_TRACE_ERROR("btm_read_remote_ext_features_complete num_page=%d invalid",
1104+ page_num);
1105+ return;
1106+ }
1107+
1108+ if (page_num > max_page) {
1109+ BTM_TRACE_WARNING(
1110+ "btm_read_remote_ext_features_complete num_page=%d, max_page=%d "
1111+ "invalid", page_num, max_page);
1112+ }
1113+
10921114 p_acl_cb = &btm_cb.acl_db[acl_idx];
10931115
10941116 /* Copy the received features page */
--- a/stack/btm/btm_int.h
+++ b/stack/btm/btm_int.h
@@ -117,7 +117,7 @@ extern uint16_t btm_get_acl_disc_reason_code(void);
117117 extern tBTM_STATUS btm_remove_acl(const RawAddress& bd_addr,
118118 tBT_TRANSPORT transport);
119119 extern void btm_read_remote_features_complete(uint8_t* p);
120-extern void btm_read_remote_ext_features_complete(uint8_t* p);
120+extern void btm_read_remote_ext_features_complete(uint8_t* p, uint8_t evt_len);
121121 extern void btm_read_remote_ext_features_failed(uint8_t status,
122122 uint16_t handle);
123123 extern void btm_read_remote_version_complete(uint8_t* p);
--- a/stack/btu/btu_hcif.cc
+++ b/stack/btu/btu_hcif.cc
@@ -70,7 +70,8 @@ static void btu_hcif_authentication_comp_evt(uint8_t* p);
7070 static void btu_hcif_rmt_name_request_comp_evt(uint8_t* p, uint16_t evt_len);
7171 static void btu_hcif_encryption_change_evt(uint8_t* p);
7272 static void btu_hcif_read_rmt_features_comp_evt(uint8_t* p);
73-static void btu_hcif_read_rmt_ext_features_comp_evt(uint8_t* p);
73+static void btu_hcif_read_rmt_ext_features_comp_evt(uint8_t* p,
74+ uint8_t evt_len);
7475 static void btu_hcif_read_rmt_version_comp_evt(uint8_t* p);
7576 static void btu_hcif_qos_setup_comp_evt(uint8_t* p);
7677 static void btu_hcif_command_complete_evt(BT_HDR* response, void* context);
@@ -194,7 +195,7 @@ void btu_hcif_process_event(UNUSED_ATTR uint8_t controller_id, BT_HDR* p_msg) {
194195 btu_hcif_read_rmt_features_comp_evt(p);
195196 break;
196197 case HCI_READ_RMT_EXT_FEATURES_COMP_EVT:
197- btu_hcif_read_rmt_ext_features_comp_evt(p);
198+ btu_hcif_read_rmt_ext_features_comp_evt(p, hci_evt_len);
198199 break;
199200 case HCI_READ_RMT_VERSION_COMP_EVT:
200201 btu_hcif_read_rmt_version_comp_evt(p);
@@ -791,7 +792,8 @@ static void btu_hcif_read_rmt_features_comp_evt(uint8_t* p) {
791792 * Returns void
792793 *
793794 ******************************************************************************/
794-static void btu_hcif_read_rmt_ext_features_comp_evt(uint8_t* p) {
795+static void btu_hcif_read_rmt_ext_features_comp_evt(uint8_t* p,
796+ uint8_t evt_len) {
795797 uint8_t* p_cur = p;
796798 uint8_t status;
797799 uint16_t handle;
@@ -799,7 +801,7 @@ static void btu_hcif_read_rmt_ext_features_comp_evt(uint8_t* p) {
799801 STREAM_TO_UINT8(status, p_cur);
800802
801803 if (status == HCI_SUCCESS)
802- btm_read_remote_ext_features_complete(p);
804+ btm_read_remote_ext_features_complete(p, evt_len);
803805 else {
804806 STREAM_TO_UINT16(handle, p_cur);
805807 btm_read_remote_ext_features_failed(status, handle);
--- a/stack/include/hcidefs.h
+++ b/stack/include/hcidefs.h
@@ -1296,6 +1296,8 @@ typedef struct {
12961296
12971297 #define HCI_FEATURE_BYTES_PER_PAGE 8
12981298
1299+#define HCI_EXT_FEATURES_SUCCESS_EVT_LEN 13
1300+
12991301 #define HCI_FEATURES_KNOWN(x) \
13001302 (((x)[0] | (x)[1] | (x)[2] | (x)[3] | (x)[4] | (x)[5] | (x)[6] | (x)[7]) != 0)
13011303