diff --git a/RF24Gateway.cpp b/RF24Gateway.cpp index e394541..729cfb7 100644 --- a/RF24Gateway.cpp +++ b/RF24Gateway.cpp @@ -396,7 +396,7 @@ void ESBGateway::handleRadioIn() msgStruct msg; - if (f.message_size > 0) { + if (f.message_size > 0 && f.message_size <= MAX_PAYLOAD_SIZE) { memcpy(&msg.message, &f.message_buffer, f.message_size); msg.size = f.message_size; @@ -494,6 +494,12 @@ void ESBGateway::handleRadioOut() std::uint8_t* tmp = msgTx->message; + // Ensure that at the length of the payload includes at least the MAC address + if (msgTx->size < 6) { + txQueue.pop(); + continue; + } + if (!config_TUN) { // TAP can use RF24Mesh for address assignment, but will still use ARP for address resolution uint32_t RF24_STR = 0x34324652; // Identifies the mac as an RF24 mac @@ -551,6 +557,12 @@ void ESBGateway::handleRadioOut() } else { // TUN always needs to use RF24Mesh for address assignment AND resolution + // Ensure that at least the 20-byte TCP/IP header is available + if (msgTx->size < 20) { + txQueue.pop(); + continue; + } + uint8_t lastOctet = tmp[19]; int16_t meshAddr; @@ -758,6 +770,9 @@ void ESBGateway::sendUDP(uint8_t nodeID, RF24Network uint8_t buffer[MAX_PAYLOAD_SIZE + 11]; + if (frame.message_size > MAX_PAYLOAD_SIZE) { + return; + } memcpy(&buffer[0], &nodeID, 1); memcpy(&buffer[1], &frame.header, 8); memcpy(&buffer[9], &frame.message_size, 2);