All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] sdp: Prevent integer underflow in string attribute length calculation
@ 2026-10-07 19:48 Hui Peng
  2026-10-07 23:54 ` bluez.test.bot
  0 siblings, 1 reply; 2+ messages in thread
From: Hui Peng @ 2026-10-07 19:48 UTC (permalink / raw)
  To: Marcel Holtmann, Johan Hovold, Luiz Augusto von Dentz
  Cc: linux-bluetooth, Hui Peng

In lib/bluetooth/sdp.c, attribute string length calculations subtract
sizeof(uint8_t) from d->unitSize (e.g. d->unitSize - sizeof(uint8_t)).
When d->unitSize is 0 or less than sizeof(uint8_t), this subtraction
underflows in 32-bit integer arithmetic to a negative/huge length value,
passing invalid sizes to memory allocation and length extraction
functions.

Add explicit lower-bound guards to ensure that when
d->unitSize <= sizeof(uint8_t), the calculated string length is safely
set to 0.

Assisted-by: Antigravity
---
 lib/bluetooth/sdp.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/lib/bluetooth/sdp.c b/lib/bluetooth/sdp.c
index 1e027f9..a750274 100644
--- a/lib/bluetooth/sdp.c
+++ b/lib/bluetooth/sdp.c
@@ -730,7 +730,10 @@ static int sdp_get_data_size(sdp_buf_t *buf, sdp_data_t *d)
 	case SDP_URL_STR8:
 	case SDP_URL_STR16:
 	case SDP_URL_STR32:
-		data_size = d->unitSize - sizeof(uint8_t);
+		if (d->unitSize > sizeof(uint8_t))
+			data_size = d->unitSize - sizeof(uint8_t);
+		else
+			data_size = 0;
 		break;
 	case SDP_SEQ8:
 	case SDP_SEQ16:
@@ -1524,7 +1527,8 @@ static void *sdp_data_value(sdp_data_t *data, uint32_t *len)
 	case SDP_TEXT_STR32:
 		val = data->val.str;
 		if (len)
-			*len = data->unitSize - sizeof(uint8_t);
+			*len = (data->unitSize > sizeof(uint8_t)) ?
+				(data->unitSize - sizeof(uint8_t)) : 0;
 		break;
 	case SDP_ALT8:
 	case SDP_ALT16:
@@ -4852,7 +4856,8 @@ int sdp_set_supp_feat(sdp_record_t *rec, const sdp_list_t *sf)
 			case SDP_TEXT_STR8:
 			case SDP_TEXT_STR16:
 				vals[j] = data->val.str;
-				lengths[j] = data->unitSize - sizeof(uint8_t);
+				lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
+					(data->unitSize - sizeof(uint8_t)) : 0;
 				break;
 			case SDP_ALT8:
 			case SDP_ALT16:
@@ -4929,7 +4934,8 @@ int sdp_get_supp_feat(const sdp_record_t *rec, sdp_list_t **seqp)
 			case SDP_TEXT_STR8:
 			case SDP_TEXT_STR16:
 				val = dd->val.str;
-				length = dd->unitSize - sizeof(uint8_t);
+				length = (dd->unitSize > sizeof(uint8_t)) ?
+					(dd->unitSize - sizeof(uint8_t)) : 0;
 				break;
 			case SDP_UINT8:
 			case SDP_UINT16:
-- 
2.47.3

^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-07 23:54 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 19:48 [PATCH] sdp: Prevent integer underflow in string attribute length calculation Hui Peng
2026-10-07 23:54 ` bluez.test.bot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.