From 96603c68f5a55dd3b6c50dc0a5310a5c1c57a677 Mon Sep 17 00:00:00 2001 From: Prasad Alatkar Date: Wed, 14 Apr 2021 20:55:41 +0530 Subject: [PATCH] nimble/host: Fix MITM vulnerability during public key exchange in secure connection --- nimble/host/src/ble_sm_sc.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/nimble/host/src/ble_sm_sc.c b/nimble/host/src/ble_sm_sc.c index 562f33b51..333310702 100644 --- a/nimble/host/src/ble_sm_sc.c +++ b/nimble/host/src/ble_sm_sc.c @@ -611,6 +611,13 @@ ble_sm_sc_public_key_rx(uint16_t conn_handle, struct os_mbuf **om, } cmd = (struct ble_sm_public_key *)(*om)->om_data; + /* Check if the peer public key is same as our generated public key. + * Return fail if the public keys match. */ + if (memcmp(cmd, ble_sm_sc_pub_key, 64) == 0) { + res->enc_cb = 1; + res->sm_err = BLE_SM_ERR_AUTHREQ; + return; + } ble_hs_lock(); proc = ble_sm_proc_find(conn_handle, BLE_SM_PROC_STATE_PUBLIC_KEY, -1,