commit | 09591ec257b3547348e0e3ba123523ea8361c84d | [log] [tgz] |
---|---|---|
author | Alisher Alikhodjaev <alisher@google.com> | Tue Jan 31 19:04:09 2023 -0800 |
committer | Android Build Coastguard Worker <android-build-coastguard-worker@google.com> | Tue Feb 14 18:19:34 2023 +0000 |
tree | 62bf7c433d34615417946202470a32cd5c423889 | |
parent | c6cf0aaac8a0c6a662aaae9df8663897ac51f263 [diff] |
OOBW in nci_snd_set_routing_cmd() Bug: 264879662 Test: read a tag, nfc on/off Change-Id: I408cf611fb35e9467d7484165ce48759970b158a (cherry picked from commit 1dd4d2e1b481dd83ca2b222993fdb74ae5306c78) Merged-In: I408cf611fb35e9467d7484165ce48759970b158a
diff --git a/src/nfc/nci/nci_hmsgs.cc b/src/nfc/nci/nci_hmsgs.cc index ed7caaa..81497c8 100644 --- a/src/nfc/nci/nci_hmsgs.cc +++ b/src/nfc/nci/nci_hmsgs.cc
@@ -632,6 +632,10 @@ uint8_t* pp; uint8_t size = tlv_size + 2; + if (size < tlv_size) { + return (NCI_STATUS_FAILED); + } + if (tlv_size == 0) { /* just to terminate routing table * 2 bytes (more=FALSE and num routing entries=0) */