mirror of
https://github.com/ArduPilot/ardupilot.git
synced 2026-10-06 19:00:27 +08:00
AP_MAVLinkCAN: reject negative CAN bus index in filter modify
A malformed CAN_FILTER_MODIFY message with a bus value of zero produces bus == -1 after the off-by-one adjustment. The existing bounds check only tested the upper bound, so hal.can[-1] was dereferenced before validation. Add a lower-bound check, matching the fix applied to MAV_CMD_CAN_FORWARD. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
committed by
Andrew Tridgell
co-authored by
Claude Opus 4.8
parent
2ab74e790d
commit
562d10e20f
@@ -207,7 +207,7 @@ void AP_MAVLinkCAN::_handle_can_filter_modify(const mavlink_message_t &msg)
|
||||
mavlink_can_filter_modify_t p;
|
||||
mavlink_msg_can_filter_modify_decode(&msg, &p);
|
||||
const int8_t bus = int8_t(p.bus)-1;
|
||||
if (bus >= HAL_NUM_CAN_IFACES || hal.can[bus] == nullptr) {
|
||||
if (bus < 0 || bus >= HAL_NUM_CAN_IFACES || hal.can[bus] == nullptr) {
|
||||
return;
|
||||
}
|
||||
if (p.num_ids > ARRAY_SIZE(p.ids)) {
|
||||
|
||||
Reference in New Issue
Block a user