]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
Bluetooth: eir: Fix possible crashes on eir_create_adv_data
authorLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Tue, 24 Mar 2026 02:34:02 +0000 (10:34 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 11 Apr 2026 12:16:38 +0000 (14:16 +0200)
[ Upstream commit 47c03902269aff377f959dc3fd94a9733aa31d6e ]

eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER
without checking if that would fit.

Link: https://github.com/bluez/bluez/issues/1117#issuecomment-2958244066
Fixes: 01ce70b0a274 ("Bluetooth: eir: Move EIR/Adv Data functions to its own file")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Use pdu.data instead of pdu->data in hci_set_ext_adv_data_sync()
 to keep context consistency. ]
Signed-off-by: Robert Garcia <rob_garcia@163.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/bluetooth/eir.c
net/bluetooth/eir.h
net/bluetooth/hci_sync.c

index 3e1713673ecc93403d662238fcc13ad7a9e834e1..3f72111ba651f9c8be32a1a73c05258bec136b07 100644 (file)
@@ -242,7 +242,7 @@ u8 eir_create_per_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr)
        return ad_len;
 }
 
-u8 eir_create_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr)
+u8 eir_create_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr, u8 size)
 {
        struct adv_info *adv = NULL;
        u8 ad_len = 0, flags = 0;
@@ -286,7 +286,7 @@ u8 eir_create_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr)
                /* If flags would still be empty, then there is no need to
                 * include the "Flags" AD field".
                 */
-               if (flags) {
+               if (flags && (ad_len + eir_precalc_len(1) <= size)) {
                        ptr[0] = 0x02;
                        ptr[1] = EIR_FLAGS;
                        ptr[2] = flags;
@@ -316,7 +316,8 @@ skip_flags:
                }
 
                /* Provide Tx Power only if we can provide a valid value for it */
-               if (adv_tx_power != HCI_TX_POWER_INVALID) {
+               if (adv_tx_power != HCI_TX_POWER_INVALID &&
+                   (ad_len + eir_precalc_len(1) <= size)) {
                        ptr[0] = 0x02;
                        ptr[1] = EIR_TX_POWER;
                        ptr[2] = (u8)adv_tx_power;
index 0df19f2f4af94499defe78897e8c78fd0dbc2daf..4497f8fd5fefb5eed4d70477fb0fdf9feebe7fe4 100644 (file)
@@ -9,7 +9,7 @@
 
 void eir_create(struct hci_dev *hdev, u8 *data);
 
-u8 eir_create_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr);
+u8 eir_create_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr, u8 size);
 u8 eir_create_scan_rsp(struct hci_dev *hdev, u8 instance, u8 *ptr);
 u8 eir_create_per_adv_data(struct hci_dev *hdev, u8 instance, u8 *ptr);
 
index 01b23fc71e6104fe8479d4b98842165d6cab923c..c6f9d07a4819481542b5644343b62e774044af7a 100644 (file)
@@ -1248,7 +1248,8 @@ static int hci_set_ext_adv_data_sync(struct hci_dev *hdev, u8 instance)
                        return 0;
        }
 
-       len = eir_create_adv_data(hdev, instance, pdu.data);
+       len = eir_create_adv_data(hdev, instance, pdu.data,
+                                 HCI_MAX_EXT_AD_LENGTH);
 
        pdu.cp.length = len;
        pdu.cp.handle = instance;
@@ -1279,7 +1280,7 @@ static int hci_set_adv_data_sync(struct hci_dev *hdev, u8 instance)
 
        memset(&cp, 0, sizeof(cp));
 
-       len = eir_create_adv_data(hdev, instance, cp.data);
+       len = eir_create_adv_data(hdev, instance, cp.data, sizeof(cp.data));
 
        /* There's nothing to do if the data hasn't changed */
        if (hdev->adv_data_len == len &&