OSDN Git Service

AVDTP: Prevent OOB read when parsing rejected response
authorCheney Ni <cheneyni@google.com>
Fri, 7 Feb 2020 11:42:42 +0000 (19:42 +0800)
committerMyles Watson <mylesgw@google.com>
Wed, 12 Feb 2020 17:32:29 +0000 (17:32 +0000)
commitc49665a9f9e8456beb59d6006c18a15697b3e7b9
treef7bb96217d27cb74ee938d90727565fcd39785d7
parentac8c0547df6f5842d9fb87530b537d2b2bae66c6
AVDTP: Prevent OOB read when parsing rejected response

Because different AVDTP rejected response has different fields, we check
its data length based on the signal to prevent OOB read.

Bug: 79702484
Test: PoC
Change-Id: Iddb887c79bd8a2caa2ae5f21af15219807f9dd63
stack/avdt/avdt_msg.cc