From: Bastien Nocera <hadess@hadess.net>
To: linux-bluetooth@vger.kernel.org
Cc: Elman Shahbazov <shahbazovelman97@gmail.com>
Subject: [BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test
Date: Tue, 4 Aug 2026 14:44:49 +0200 [thread overview]
Message-ID: <20260804124511.2212066-2-hadess@hadess.net> (raw)
In-Reply-To: <20260804124511.2212066-1-hadess@hadess.net>
Adapt poc_avrcp_oob.c and poc_folder_oob.c into unit tests.
Co-authored-by: Elman Shahbazov <shahbazovelman97@gmail.com>
---
Makefile.am | 9 +++++
unit/test-avrcp-sec.c | 76 +++++++++++++++++++++++++++++++++++++++++++
2 files changed, 85 insertions(+)
create mode 100644 unit/test-avrcp-sec.c
diff --git a/Makefile.am b/Makefile.am
index 19c468d3a504..e3baa4155c1f 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -660,6 +660,15 @@ unit_test_avrcp_SOURCES = unit/test-avrcp.c \
unit_test_avrcp_LDADD = lib/libbluetooth-internal.la \
src/libshared-glib.la $(GLIB_LIBS)
+unit_tests += unit/test-avrcp-sec
+
+unit_test_avrcp_sec_SOURCES = unit/test-avrcp-sec.c \
+ profiles/audio/avrcp-parse.c \
+ profiles/audio/avrcp-parse.h \
+ src/log.h src/log.c
+unit_test_avrcp_sec_LDADD = lib/libbluetooth-internal.la \
+ src/libshared-glib.la $(GLIB_LIBS)
+
unit_tests += unit/test-hfp
unit_test_hfp_SOURCES = unit/test-hfp.c
diff --git a/unit/test-avrcp-sec.c b/unit/test-avrcp-sec.c
new file mode 100644
index 000000000000..a100b2d68e35
--- /dev/null
+++ b/unit/test-avrcp-sec.c
@@ -0,0 +1,76 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ *
+ * BlueZ - Bluetooth protocol stack for Linux
+ *
+ * Copyright (C) 2026 Red Hat Inc.
+ *
+ *
+ */
+
+#ifdef HAVE_CONFIG_H
+#include <config.h>
+#endif
+
+#include <glib.h>
+
+#include "src/shared/util.h"
+#include "src/shared/tester.h"
+#include "src/log.h"
+
+#include "profiles/audio/avrcp-parse.h"
+
+static void avrcp_element_name_oob(gconstpointer data)
+{
+ char name[255];
+ uint16_t namesize;
+ gboolean ret;
+
+ /* Crafting a malicious payload.
+ * Actual packet length (len) = 14 bytes */
+ uint8_t malicious_packet[14] = {0};
+
+ /* Specify namesize = 1000 (0x03E8 in Big Endian) at offset 11 */
+ malicious_packet[11] = 0x03;
+ malicious_packet[12] = 0xE8;
+
+ /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */
+ ret = parse_media_element_name(malicious_packet, sizeof(malicious_packet),
+ name, &namesize);
+ if (ret)
+ tester_test_passed();
+ else
+ tester_test_failed();
+}
+
+static void avrcp_folder_name_oob(gconstpointer data)
+{
+ char name[255];
+ gboolean ret;
+
+ /* Crafting a malicious payload.
+ * Actual packet length (len) = 14 bytes */
+ uint8_t malicious_packet[14] = {0};
+
+ /* Specify namesize = 1000 (0x03E8 in Big Endian) at offset 12 */
+ malicious_packet[12] = 0x03;
+ malicious_packet[13] = 0xE8;
+
+ /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */
+ ret = parse_media_folder_name(malicious_packet, sizeof(malicious_packet),
+ name);
+ if (ret)
+ tester_test_passed();
+ else
+ tester_test_failed();
+}
+
+int main(int argc, char *argv[])
+{
+ tester_init(&argc, &argv);
+
+ tester_add("/avrcp-element-name-oob", NULL, NULL, avrcp_element_name_oob, NULL);
+ tester_add("/avrcp-folder-name-oob", NULL, NULL, avrcp_folder_name_oob, NULL);
+
+ return tester_run();
+}
--
2.55.0
next prev parent reply other threads:[~2026-08-04 12:45 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 12:44 [BlueZ 1/3] avrcp: Split off name parsing from parse_*_element() Bastien Nocera
2026-08-04 12:44 ` Bastien Nocera [this message]
2026-08-04 12:44 ` [BlueZ 3/3] avrcp: Fix Out-of-Bounds Read in AVRCP GetFolderItems parsing Bastien Nocera
2026-08-04 13:49 ` [BlueZ,1/3] avrcp: Split off name parsing from parse_*_element() bluez.test.bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804124511.2212066-2-hadess@hadess.net \
--to=hadess@hadess.net \
--cc=linux-bluetooth@vger.kernel.org \
--cc=shahbazovelman97@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox